CVE-2023-22523

This vulnerability, if exploited, allows an attacker to perform privileged RCE (Remote Code Execution) on machines with the Assets Discovery agent installed. The vulnerability exists between the Assets Discovery application (formerly known as Insight Discovery) and the Assets Discovery agent.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
atlassianCNA
9.8 CRITICAL
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 93%
VendorProductVersion
atlassianassets_discovery_cloud
1.0.0 ≤
𝑥
< 3.2.0
atlassianassets_discovery_data_center
1.0.0 ≤
𝑥
≤ 3.1.11
atlassianassets_discovery_data_center
6.0.0 ≤
𝑥
< 6.2.0
atlassianassets_discovery_data_server
1.0.0 ≤
𝑥
≤ 3.1.11
atlassianassets_discovery_data_server
6.0.0 ≤
𝑥
< 6.2.0
𝑥
= Vulnerable software versions