Atlassian and Finland’s National Cyber Security Centre warned of multiple severe vulnerabilities in Atlassian products, led by CVE-2022-1471, a critical SnakeYAML deserialization flaw rated CVSS 9.8 that can enable remote code execution across Bitbucket, Confluence, Jira Core, Jira Software, Jira Service Management, Automation for Jira, and the Confluence Cloud Migration App. Atlassian said its hosted atlassian.net cloud sites are not affected, but Data Center and Server deployments face broad exposure and should be upgraded immediately to fixed releases.
The advisories also identified product-specific RCE issues in Confluence Data Center and Server (CVE-2023-22522), the Assets Discovery app (CVE-2023-22523), and Atlassian Companion App for macOS (CVE-2023-22524). Authorities urged organizations to install patched versions without delay and, where patching cannot be completed at once, remove vulnerable services from the public internet; Atlassian added that there is no mitigation for some affected products, while certain Jira and Jira Service Management environments can reduce risk by upgrading the Automation for Jira app to a fixed version.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
The December 7 notice specified that only the Assets Discovery add-on was affected by CVE-2023-22523 and that the Windows version of Atlassian Companion App was not affected by CVE-2023-22524. It also highlighted fixed versions for Confluence, Assets Discovery, and Atlassian Companion App for macOS.
On December 7, 2023, Traficom's Kyberturvallisuuskeskus issued a security notice warning about several serious Atlassian vulnerabilities, including CVE-2022-1471 and product-specific RCE flaws CVE-2023-22522, CVE-2023-22523, and CVE-2023-22524. The notice urged organizations to immediately install fixed versions or remove vulnerable services from the public internet until patching could be completed.
In its advisory, Atlassian listed affected products including Bitbucket, Confluence, Jira Core, Jira Software, Jira Service Management, Automation for Jira, and the Confluence Cloud Migration App, and provided fixed versions. It also stated that Jira and Jira Service Management could in some cases be fully mitigated by upgrading the Automation for Jira app, while some other products had no workaround short of upgrading.
On December 5, 2023, Atlassian disclosed CVE-2022-1471, a critical SnakeYAML deserialization vulnerability rated CVSS 9.8 that can lead to remote code execution in multiple Data Center and Server products. Atlassian said Cloud sites hosted on atlassian.net were not affected and urged customers to upgrade immediately, noting limited mitigation options for some products.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
kyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourceconfluence.atlassian.com
Open sourceconfluence.atlassian.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.