Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Facebook X (Twitter) Instagram
    Tech Empire Solutions
    • Home
    • Cloud
    • Cyber Security
    • Technology
    • Business Solution
    • Tech Gadgets
    Tech Empire Solutions
    Home » Atlassian releases fixes for more than 20 defects, including critical Bamboo bug
    Cyber Security

    Atlassian releases fixes for more than 20 defects, including critical Bamboo bug

    techempireBy techempire3 Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email

    ReportMarch 21, 2024Editorial DepartmentDatabases/vulnerabilities

    bamboo insect

    Atlassian has released patches for more than two dozen security vulnerabilities, including a critical bug affecting Bamboo data centers and servers that could be exploited without user interaction.

    Tracked as CVE-2024-1597the vulnerability has a CVSS score of 10.0, indicating the highest severity.

    It is described as a SQL injection flaw that is rooted in a dependency called org.postgresql:postgresql, so the company says that despite its importance, the “assessed risk is low.”

    Internet security

    “This org.postgresql:postgresql dependency vulnerability […] Potentially allowing an unauthenticated attacker to expose vulnerable assets in your environment to exploitation, with significant impact on confidentiality, integrity, availability, and without requiring user interaction,” Atlassian said.

    According to the description of the flaw in the NIST National Vulnerability Database (NVD), “The PostgreSQL JDBC driver pgjdbc allows an attacker to inject SQL when using PreferQueryMode=SIMPLE.” Driver versions prior to the ones listed below are affected Influence –

    • 42.7.2
    • 42.6.1
    • 42.5.5
    • 42.4.4
    • 42.3.9, and
    • 42.2.28 (also fixed in 42.2.28.jre7)

    “SQL injection is possible when using the non-default connection attribute preferQueryMode=simple in conjunction with application code that has vulnerable SQL that negates parameters,” the maintainers said in an advisory last month. value.”

    “The driver is not vulnerable when using the default query mode. Users who do not override the query mode are not affected.”

    Internet security

    The Atlassian vulnerability is said to have been introduced in the following versions of Bamboo Data Center and Server –

    • 8.2.1
    • 9.0.0
    • 9.1.0
    • 9.2.1
    • 9.3.0
    • 9.4.0, and
    • 9.5.0

    The company also emphasized that Bamboo and other Atlassian Data Center products are not affected by CVE-2024-1597 because they do not use PreferQueryMode=SIMPLE in their SQL database connection settings.

    SonarSource security researcher Paul Gerste is credited with discovering and reporting the flaw. Users are advised to update their instances to the latest version to protect against any potential threats.

    Did you find this article interesting?follow us Twitter  and LinkedIn to read more exclusive content from us.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    techempire
    • Website

    Related Posts

    Ongoing campaign bombards businesses with spam emails and phone calls

    6 common mistakes organizations make when deploying advanced authentication

    New Chrome zero-day vulnerability CVE-2024-4761 is being actively exploited

    Microsoft patches 61 flaws, including two actively exploited zero-day vulnerabilities

    Dutch court sentences Tornado Cash co-founder to 5 years in prison for money laundering

    Migrate from VMware vSphere to Microsoft Azure

    Leave A Reply Cancel Reply

    Top Reviews
    Editors Picks

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Mr. Meowski’s Bakery To Re-Locate In St. Charles MO

    Legal Pages
    • About Us
    • Disclaimer
    • DMCA
    • Privacy Policy
    Our Picks

    Gateway Studios High-Tech Recording Studio To Open In Chesterfield, Missouri

    Edufox

    Emerging Academic Education Platforms – Sponsored By Edufox

    Top Reviews

    Type above and press Enter to search. Press Esc to cancel.