« Volver al listado

CVE-2023-22524

Estado: ModificadaCrítica (9.8)—

Certain versions of the Atlassian Companion App for MacOS were affected by a remote code execution vulnerability. An attacker could utilize WebSockets to bypass Atlassian Companion’s blocklist and MacOS Gatekeeper to allow execution of code.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-22524",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-22524",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2023-12-19T05:00:20.476961Z"
        }
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Secondary",
        "source": "security@atlassian.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.0",
          "baseScore": 9.6,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 2.8
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@atlassian.com",
      "affectedData": [
        {
          "vendor": "Atlassian",
          "product": "Companion for Mac",
          "versions": [
            {
              "status": "unaffected",
              "version": "< 1.0.0"
            },
            {
              "status": "affected",
              "version": ">= 1.0.0"
            },
            {
              "status": "affected",
              "version": ">= 1.1.0"
            },
            {
              "status": "affected",
              "version": ">= 1.2.0"
            },
            {
              "status": "affected",
              "version": ">= 1.2.2"
            },
            {
              "status": "affected",
              "version": ">= 1.2.3"
            },
            {
              "status": "affected",
              "version": ">= 1.2.4"
            },
            {
              "status": "affected",
              "version": ">= 1.2.5"
            },
            {
              "status": "affected",
              "version": ">= 1.2.6"
            },
            {
              "status": "affected",
              "version": ">= 1.3.0"
            },
            {
              "status": "affected",
              "version": ">= 1.3.1"
            },
            {
              "status": "affected",
              "version": ">= 1.4.1"
            },
            {
              "status": "affected",
              "version": ">= 1.4.2"
            },
            {
              "status": "affected",
              "version": ">= 1.4.3"
            },
            {
              "status": "affected",
              "version": ">= 1.4.4"
            },
            {
              "status": "affected",
              "version": ">= 1.4.5"
            },
            {
              "status": "affected",
              "version": ">= 1.4.6"
            },
            {
              "status": "affected",
              "version": ">= 1.5.0"
            },
            {
              "status": "affected",
              "version": ">= 1.6.0"
            },
            {
              "status": "affected",
              "version": ">= 1.6.1"
            },
            {
              "status": "unaffected",
              "version": ">= 2.0.0"
            },
            {
              "status": "unaffected",
              "version": ">= 2.0.1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2023-12-06T05:15:10.267",
  "references": [
    {
      "url": "https://confluence.atlassian.com/security/cve-2023-22524-rce-vulnerability-in-atlassian-companion-app-for-macos-1319249492.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@atlassian.com"
    },
    {
      "url": "https://jira.atlassian.com/browse/CONFSERVER-93518",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@atlassian.com"
    },
    {
      "url": "https://confluence.atlassian.com/security/cve-2023-22524-rce-vulnerability-in-atlassian-companion-app-for-macos-1319249492.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://jira.atlassian.com/browse/CONFSERVER-93518",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Certain versions of the Atlassian Companion App for MacOS were affected by a remote code execution vulnerability. An attacker could utilize WebSockets to bypass Atlassian Companion’s blocklist and MacOS Gatekeeper to allow execution of code."
    },
    {
      "lang": "es",
      "value": "Ciertas versiones de la aplicación Atlassian Companion para MacOS se vieron afectadas por una vulnerabilidad de ejecución remota de código. Un atacante podría utilizar WebSockets para eludir la lista de bloqueo de Atlassian Companion y MacOS Gatekeeper para permitir la ejecución de código."
    }
  ],
  "lastModified": "2026-06-17T05:35:38.137",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:atlassian:companion:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8D3069A1-74AE-4FF2-9C2F-B76AF7B92A5E",
              "versionEndExcluding": "2.0.0",
              "versionStartIncluding": "1.0.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "387021A0-AF36-463C-A605-32EA7DAC172E"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "security@atlassian.com"
}