PT-2023-8847 · Atlassian+1 · Bamboo Server+4

Adam Korczynski

·

Publicado

2023-09-29

·

Atualizado

2024-08-02

·

CVE-2023-39410

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Apache Avro Java SDK versions up to and including 1.11.2 Confluence Data Center versions from 7.17.0 to 8.7.1 Confluence Data Center versions from 8.7.0 to 8.7.1 Confluence Server versions from 7.17.0 to 8.5.4 LTS Bamboo Data Center and Server versions 9.2.1, 9.3.0, and 9.4.0
Description When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK. An unauthenticated attacker can expose assets in the environment susceptible to exploitation, with no impact to confidentiality, no impact to integrity, high impact to availability, and requires no user interaction.
Recommendations For Apache Avro Java SDK versions up to and including 1.11.2, update to apache-avro version 1.11.3. For Confluence Data Center versions from 7.17.0 to 8.7.1, upgrade to the latest version, or to one of the specified supported fixed versions: 8.8.0, 8.7.2, 8.6.2, 8.5.4 LTS, 8.5.5 LTS, 8.5.6 LTS, 7.19.17 LTS, 7.19.18 LTS, 7.19.19 LTS. For Confluence Server versions from 7.17.0 to 8.5.4 LTS, upgrade to the latest 8.5.x LTS version, or to one of the specified supported fixed versions: 8.5.5 LTS, 8.5.6 LTS, 7.19.17 LTS, 7.19.18 LTS, 7.19.19 LTS. For Bamboo Data Center and Server versions 9.2.1, 9.3.0, and 9.4.0, upgrade to the latest version, or to one of the specified supported fixed versions: 9.2.8, 9.3.6, 9.4.2.

Correção

DoS

Deserialization of Untrusted Data

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-02310
CVE-2023-39410
GHSA-RHRV-645H-FJFH
OESA-2024-1809
OESA-2024-1915
OESA-2024-1916
OESA-2024-1917
OESA-2024-1918
PYSEC-2023-188
RHSA-2023:7637
RHSA-2023:7638
RHSA-2023:7639
RHSA-2024:10207
RHSA-2024:10208

Produtos afetados

Apache Avro Java Sdk
Bamboo
Bamboo Server
Confluence
Jira