Show plain JSON{"id": "CVE-2023-22523", "cveTags": [], "metrics": {"cvssMetricV30": [{"type": "Secondary", "source": "security@atlassian.com", "cvssData": {"scope": "UNCHANGED", "version": "3.0", "baseScore": 9.8, "attackVector": "NETWORK", "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 3.9}], "cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 8.8, "attackVector": "NETWORK", "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "LOW", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 2.8}]}, "published": "2023-12-06T05:15:10.087", "references": [{"url": "https://confluence.atlassian.com/security/cve-2023-22523-rce-vulnerability-in-assets-discovery-1319248914.html", "tags": ["Vendor Advisory"], "source": "security@atlassian.com"}, {"url": "https://jira.atlassian.com/browse/JSDSERVER-14925", "tags": ["Issue Tracking", "Vendor Advisory"], "source": "security@atlassian.com"}], "vulnStatus": "Analyzed", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "NVD-CWE-noinfo"}]}], "descriptions": [{"lang": "en", "value": "This vulnerability, if exploited, allows an attacker to perform privileged RCE (Remote Code Execution) on machines with the Assets Discovery agent installed. The vulnerability exists between the Assets Discovery application (formerly known as Insight Discovery) and the Assets Discovery agent."}, {"lang": "es", "value": "Esta vulnerabilidad, si se explota, permite a un atacante realizar RCE (ejecuci\u00f3n remota de c\u00f3digo) privilegiada en m\u00e1quinas con el agente Assets Discovery instalado. La vulnerabilidad existe entre la aplicaci\u00f3n Assets Discovery (anteriormente conocida como Insight Discovery) y el agente Assets Discovery."}], "lastModified": "2023-12-11T18:29:13.970", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:atlassian:assets_discovery_cloud:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B605B443-2604-4D2D-99C2-EF7D955B1886", "versionEndExcluding": "3.2.0", "versionStartIncluding": "1.0.0"}, {"criteria": "cpe:2.3:a:atlassian:assets_discovery_data_center:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6EE9C216-E2F8-4BDB-A67B-095AA0B19613", "versionEndIncluding": "3.1.11", "versionStartIncluding": "1.0.0"}, {"criteria": "cpe:2.3:a:atlassian:assets_discovery_data_center:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C95EF896-3AE4-400B-B4BD-61D909D91B5B", "versionEndExcluding": "6.2.0", "versionStartIncluding": "6.0.0"}, {"criteria": "cpe:2.3:a:atlassian:assets_discovery_data_server:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "63079045-C71C-4D37-9B05-BD3705B90B37", "versionEndIncluding": "3.1.11", "versionStartIncluding": "1.0.0"}, {"criteria": "cpe:2.3:a:atlassian:assets_discovery_data_server:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "329E8EB1-FEAC-4C29-B443-4AB31D5DBC95", "versionEndExcluding": "6.2.0", "versionStartIncluding": "6.0.0"}], "operator": "OR"}]}], "sourceIdentifier": "security@atlassian.com"}