High-Severity Flaws Uncovered in Atlassian Products and ISC BIND Server
Sep 22, 2023
Server Security / Vulnerability
 Atlassian and the Internet Systems Consortium (ISC) have disclosed several security flaws impacting their products that could be exploited to achieve denial-of-service (DoS) and remote code execution.  The Australian software services provider  said  that the four high-severity flaws were fixed in new versions shipped last month. This includes -   CVE-2022-25647  (CVSS score: 7.5) - A deserialization flaw in the Google Gson package impacting Patch Management in Jira Service Management Data Center and Server  CVE-2023-22512  (CVSS score: 7.5) - A DoS flaw in Confluence Data Center and Server  CVE-2023-22513  (CVSS score: 8.5) - A RCE flaw in Bitbucket Data Center and Server  CVE-2023-28709  (CVSS score: 7.5) - A DoS flaw in Apache Tomcat server impacting Bamboo Data Center and Server   The flaws have been addressed in the following versions -   Jira Service Management Server and Data Center (versions 4.20.25, 5.4.9, 5.9.2, 5.10.1, 5.11.0, or later)  Conflue...