CVE-2023-22524
Estado: ModificadaCrítica (9.8)—
Certain versions of the Atlassian Companion App for MacOS were affected by a remote code execution vulnerability. An attacker could utilize WebSockets to bypass Atlassian Companion’s blocklist and MacOS Gatekeeper to allow execution of code.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 25%
- Percentil entre todas las CVEs puntuadas: 98
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-noinfo
Referencias
- https://confluence.atlassian.com/security/cve-2023-22524-rce-vulnerability-in-atlassian-companion-app-for-macos-1319249492.html
- https://jira.atlassian.com/browse/CONFSERVER-93518
- https://confluence.atlassian.com/security/cve-2023-22524-rce-vulnerability-in-atlassian-companion-app-for-macos-1319249492.html
- https://jira.atlassian.com/browse/CONFSERVER-93518
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-22524",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-22524",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2023-12-19T05:00:20.476961Z"
}
}
],
"cvssMetricV30": [
{
"type": "Secondary",
"source": "security@atlassian.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.0",
"baseScore": 9.6,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 2.8
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security@atlassian.com",
"affectedData": [
{
"vendor": "Atlassian",
"product": "Companion for Mac",
"versions": [
{
"status": "unaffected",
"version": "< 1.0.0"
},
{
"status": "affected",
"version": ">= 1.0.0"
},
{
"status": "affected",
"version": ">= 1.1.0"
},
{
"status": "affected",
"version": ">= 1.2.0"
},
{
"status": "affected",
"version": ">= 1.2.2"
},
{
"status": "affected",
"version": ">= 1.2.3"
},
{
"status": "affected",
"version": ">= 1.2.4"
},
{
"status": "affected",
"version": ">= 1.2.5"
},
{
"status": "affected",
"version": ">= 1.2.6"
},
{
"status": "affected",
"version": ">= 1.3.0"
},
{
"status": "affected",
"version": ">= 1.3.1"
},
{
"status": "affected",
"version": ">= 1.4.1"
},
{
"status": "affected",
"version": ">= 1.4.2"
},
{
"status": "affected",
"version": ">= 1.4.3"
},
{
"status": "affected",
"version": ">= 1.4.4"
},
{
"status": "affected",
"version": ">= 1.4.5"
},
{
"status": "affected",
"version": ">= 1.4.6"
},
{
"status": "affected",
"version": ">= 1.5.0"
},
{
"status": "affected",
"version": ">= 1.6.0"
},
{
"status": "affected",
"version": ">= 1.6.1"
},
{
"status": "unaffected",
"version": ">= 2.0.0"
},
{
"status": "unaffected",
"version": ">= 2.0.1"
}
]
}
]
}
],
"published": "2023-12-06T05:15:10.267",
"references": [
{
"url": "https://confluence.atlassian.com/security/cve-2023-22524-rce-vulnerability-in-atlassian-companion-app-for-macos-1319249492.html",
"tags": [
"Vendor Advisory"
],
"source": "security@atlassian.com"
},
{
"url": "https://jira.atlassian.com/browse/CONFSERVER-93518",
"tags": [
"Vendor Advisory"
],
"source": "security@atlassian.com"
},
{
"url": "https://confluence.atlassian.com/security/cve-2023-22524-rce-vulnerability-in-atlassian-companion-app-for-macos-1319249492.html",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://jira.atlassian.com/browse/CONFSERVER-93518",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Certain versions of the Atlassian Companion App for MacOS were affected by a remote code execution vulnerability. An attacker could utilize WebSockets to bypass Atlassian Companion’s blocklist and MacOS Gatekeeper to allow execution of code."
},
{
"lang": "es",
"value": "Ciertas versiones de la aplicación Atlassian Companion para MacOS se vieron afectadas por una vulnerabilidad de ejecución remota de código. Un atacante podría utilizar WebSockets para eludir la lista de bloqueo de Atlassian Companion y MacOS Gatekeeper para permitir la ejecución de código."
}
],
"lastModified": "2026-06-17T05:35:38.137",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:atlassian:companion:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8D3069A1-74AE-4FF2-9C2F-B76AF7B92A5E",
"versionEndExcluding": "2.0.0",
"versionStartIncluding": "1.0.0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "387021A0-AF36-463C-A605-32EA7DAC172E"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "security@atlassian.com"
}