{"id":284204,"date":"2023-07-25T20:28:43","date_gmt":"2023-07-25T18:28:43","guid":{"rendered":"https:\/\/www.borncity.com\/blog\/?p=284204"},"modified":"2023-07-26T00:31:25","modified_gmt":"2023-07-25T22:31:25","slug":"atlassian-aktualisiert-confluence-und-bambo-wegen-kritischer-schwachstellen","status":"publish","type":"post","link":"https:\/\/borncity.com\/blog\/2023\/07\/25\/atlassian-aktualisiert-confluence-und-bambo-wegen-kritischer-schwachstellen\/","title":{"rendered":"Atlassian aktualisiert Confluence und Bambo wegen kritischer Schwachstellen"},"content":{"rendered":"<p><img decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline;\" title=\"Sicherheit (Pexels, allgemeine Nutzung)\" src=\"https:\/\/borncity.com\/blog\/wp-content\/uploads\/2021\/04\/Sicherheit_klein.jpg\" alt=\"Sicherheit (Pexels, allgemeine Nutzung)\" width=\"200\" align=\"left\" \/>[<a href=\"https:\/\/borncity.com\/win\/2023\/07\/26\/atlassian-updates-confluence-and-bambo-due-to-critical-vulnerabilities\/\" target=\"_blank\" rel=\"noopener\">English<\/a>]Noch ein Nachtrag vom 18. Juli 2023 &#8211; da hat der Anbieter Atlassian sein Security Bulletin f\u00fcr Juli 2023 ver\u00f6ffentlicht. Es sind Sicherheitsl\u00fccken in Confluence Data Center &amp; Server (CVE-2023-22505 und CVE-2023-22508) sowie im Bamboo Data Center (CVE-2023-22506) \u00f6ffentlich geworden. Ein Angreifer kann diese Sicherheitsl\u00fccken ausnutzen, um die Kontrolle \u00fcber ein betroffenes System zu \u00fcbernehmen.<\/p>\n<p><!--more--><\/p>\n<p>Die US-CISA <a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2023\/07\/21\/atlassian-releases-security-updates\" target=\"_blank\" rel=\"noopener\">warnte<\/a> bereits am 21. Juli 2023 vor diesen Sicherheitsl\u00fccken und fordert zum Patchen auf. Hier die betreffende Warnung:<\/p>\n<blockquote><p>Atlassian has released its Security Bulletin for <a href=\"https:\/\/confluence.atlassian.com\/security\/security-bulletin-july-18-2023-1251417643.html\" target=\"_blank\" rel=\"noopener\">July 2023<\/a> to address vulnerabilities in Confluence Data Center &amp; Server (<a href=\"https:\/\/jira.atlassian.com\/browse\/CONFSERVER-88265\" target=\"_blank\" rel=\"noopener\">CVE-2023-22505<\/a> and <a href=\"https:\/\/jira.atlassian.com\/browse\/CONFSERVER-88221\" target=\"_blank\" rel=\"noopener\">CVE-2023-22508<\/a>) and Bamboo Data Center (<a href=\"https:\/\/jira.atlassian.com\/browse\/BAM-22400\" target=\"_blank\" rel=\"noopener\">CVE-2023-22506<\/a>). An attacker can exploit these vulnerabilities to take control of an affected system.<\/p>\n<p>CISA encourages users and administrators to review Atlassian's <a href=\"https:\/\/confluence.atlassian.com\/security\/security-bulletin-july-18-2023-1251417643.html\" target=\"_blank\" rel=\"noopener\">July 2023 Security Bulletin<\/a> and apply the necessary updates.<\/p><\/blockquote>\n<p>Die Sicherheitswarnung umfasst folgende Produkte und Schwachstellen:<\/p>\n<ul>\n<li><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-22505\" target=\"_blank\" rel=\"noopener\">CVE-2023-22505<\/a>: RCE (Remote Code Execution) in Confluence Data Center &amp; Server; High, CVSS Score 8, <a href=\"https:\/\/jira.atlassian.com\/browse\/CONFSERVER-88265\" target=\"_blank\" rel=\"noopener\">View Ticket<\/a><\/li>\n<li><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-22508\" target=\"_blank\" rel=\"noopener\">CVE-2023-22508<\/a>; RCE (Remote Code Execution) in Confluence Data Center &amp; Server; High; CVSS Score 8.5, <a href=\"https:\/\/jira.atlassian.com\/browse\/CONFSERVER-88221\" target=\"_blank\" rel=\"noopener\">View Ticket<\/a><\/li>\n<li><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-22506\" target=\"_blank\" rel=\"noopener\">CVE-2023-22506<\/a>: Injection, RCE (Remote Code Execution) in Bamboo; High; CVSS Score 7.5, <a href=\"https:\/\/jira.atlassian.com\/browse\/BAM-22400\" target=\"_blank\" rel=\"noopener\">View Ticket<\/a><\/li>\n<\/ul>\n<p>Details zu den betroffenen Softwareversionen und zu den Updates finden sich in den verlinkten Tickets. (<a href=\"https:\/\/thehackernews.com\/2023\/07\/atlassian-releases-patches-for-critical.html\" target=\"_blank\" rel=\"noopener\">via<\/a>)<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[English]Noch ein Nachtrag vom 18. Juli 2023 &#8211; da hat der Anbieter Atlassian sein Security Bulletin f\u00fcr Juli 2023 ver\u00f6ffentlicht. Es sind Sicherheitsl\u00fccken in Confluence Data Center &amp; Server (CVE-2023-22505 und CVE-2023-22508) sowie im Bamboo Data Center (CVE-2023-22506) \u00f6ffentlich geworden. &hellip; <a href=\"https:\/\/borncity.com\/blog\/2023\/07\/25\/atlassian-aktualisiert-confluence-und-bambo-wegen-kritischer-schwachstellen\/\">Weiterlesen <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[426,185],"tags":[4328,4315],"class_list":["post-284204","post","type-post","status-publish","format-standard","hentry","category-sicherheit","category-update","tag-sicherheit","tag-update"],"_links":{"self":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/posts\/284204","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/comments?post=284204"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/posts\/284204\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/media?parent=284204"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/categories?post=284204"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/tags?post=284204"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}