Initiatives for
As the national authority for Cybersecurity the CCB has developed several initiatives for specific publics which are presented here.
Reference:
Advisory #2024-09
Version:
1.0
Affected software:
Bamboo: Data Center and Server
Bitbucket: Data Center and Server
Confluence: Data Center and Server
Crowd: Data Center and Server
Jira Service Management: Data Center and Server
Jira: Data Center and Server
Type:
Remote Code Execution
CVE/CVSS:
CVE-2024-21674:CVSS 8.6(CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N)
CVE-2024-21672:CVSS 8.3(CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H)
CVE-2024-21673:CVSS 8.0(CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H)
CVE-2020-26217:CVSS 8.8(CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVE-2018-10054:CVSS 8.8(CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)Remark: the overview above only shows the vulnerabilities with a CVSS score that is higher than 8.0. Please consult the Atlassian security Bulletin for a detailed overview of all vulnerabilities.
https://confluence.atlassian.com/security/security-bulletin-january-16-2024-1333335615.html
Atlassian releases a high severity security update to address 28 vulnerabilities. The most severe ones could lead to remote code execution and are affecting Confluence Data Center and Server.
CVE-2024-21674: This vulnerability, with CVSS score of 8.6 affecting Confluence Data Center and Server, allows an unauthenticated attacker to achieve Remote Code Execution (RCE) without user interaction.
CVE-2024-21672: This vulnerability, with CVSS score of 8.3 affecting Confluence Data Center and Server, allows an unauthenticated attacker to achieve Remote Code Execution (RCE), where user interaction is required.
CVE-2024-21673: This vulnerability, with CVSS score of 8.0 affecting Confluence Data Center and Server, allows an authenticated attacker to achieve Remote Code Execution (RCE) without user interaction.
Patch
The Centre for Cybersecurity Belgium strongly recommends installing updates for vulnerable devices with the highest priority, after thorough testing.
Atlassian addressed the issues in the following versions:
Bitbucket Data Center
Bitbucket Server
Bamboo Data Center and Server
Jira Data Center and Server
Jira Service Management Data Center and Server
Crowd Data Center and Server
Confluence Data Center
Confluence Server
Monitor/Detect
The CCB recommends organizations upscale monitoring and detection capabilities to identify any related suspicious activity, ensuring a swift response in case of an intrusion.
In case of an intrusion, you can report an incident via: https://ccb.belgium.be/cert/report-incident
While patching appliances or software to the newest version may provide safety from future exploitation, it does not remediate historic compromise.
https://nvd.nist.gov/vuln/detail/CVE-2024-21673
https://nvd.nist.gov/vuln/detail/CVE-2024-21674
https://nvd.nist.gov/vuln/detail/CVE-2024-21672