CVE-2023-22524

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
06/12/2023
Last modified:
11/12/2023

Description

Certain versions of the Atlassian Companion App for MacOS were affected by a remote code execution vulnerability. An attacker could utilize WebSockets to bypass Atlassian Companion’s blocklist and MacOS Gatekeeper to allow execution of code.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:atlassian:companion:*:*:*:*:*:*:*:* 1.0.0 (including) 2.0.0 (excluding)
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*