Atlassian reveals critical flaws in almost everything it makes and touches
– is described as an arbitrary Servlet Filter bypass that means an attacker could send a specially crafted HTTP request to bypass custom Servlet Filters used by third-party apps to enforce authentication.
The scary part is that the flaw allows a remote, unauthenticated attacker to bypass authentication used by third-party apps. The really scary part is that Atlassian doesn't have a definitive list of apps that could be impacted. "Atlassian has released updates that fix the root cause of this vulnerability, but has not exhaustively enumerated all potential consequences of this vulnerability," it added.
The same CVE can also be exploited in a cross-site scripting attack: a specially crafted HTTP request can bypass the Servlet Filter used to validate legitimate Atlassian Gadgets."An attacker that can trick a user into requesting a malicious URL can execute arbitrary JavaScript in the user's browser," Atlassian explains.
Canada Latest News, Canada Headlines
Similar News:You can also read news stories similar to this one that we have collected from other news sources.
Scale of fires raging across UK on hottest day revealed in satellite images from NASA databaseNASA's fire detection database, FIRMS, shows fires in regions around the country on Tuesday as the UK experienced temperatures above forty degrees for the first time.
Read more »
Identifying a core human microbiomeIdentifying a core human microbiome Microbiome healthy immunesystem diet prokaryotes eukaryotes virome gut NGSsequencing omics Nutrients_MDPI TNO_Research Unibo UninaIT VetmeduniVienna
Read more »
Security flaws in GPS trackers put global fleets at riskSecurity flaws in GPS trackers can be abused to cut off fuel to vehicles, CISA warns
Read more »
B&M shoppers spot return of discontinued 90s Cadbury chocolatesThe confectionary brand launched the product back in 1997
Read more »
Amazon targets 10,000 fake review Facebook groupsThe groups were offering refunds for products purchased on Amazon once reviews had been posted.
Read more »
Fashion brand loved by Stacey Solomon and Gemma Atkinson loses more than £1.5mFashion brand loved by Stacey Solomon, Alison Hammond and Gemma Atkinson loses more than £1.5m
Read more »