← All CVEs

CVE-2023-22523

high · 8.8

This vulnerability, if exploited, allows an attacker to perform privileged RCE (Remote Code Execution) on machines with the Assets Discovery agent installed. The vulnerability exists between the Assets Discovery application (formerly known as Insight Discovery) and the Assets Discovery agent.

8.8
CVSS
11.1%
EPSS (exploit prob.)
96th
EPSS percentile
2023-12-06
Published

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

VendorProductAffected versions
atlassianassets_discovery_cloud>= 1.0.0, < 3.2.0
atlassianassets_discovery_data_center>= 1.0.0, <= 3.1.11
atlassianassets_discovery_data_center>= 6.0.0, < 6.2.0
atlassianassets_discovery_data_server>= 1.0.0, <= 3.1.11
atlassianassets_discovery_data_server>= 6.0.0, < 6.2.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2023-22523