CVE-2024-21682
Jira Assets Discovery Data Center vulnerability analysis and mitigation

Overview

A high severity Injection vulnerability (CVE-2024-21682) was discovered in Assets Discovery versions 1.0 through 6.2.0. Assets Discovery is a network scanning tool available via Atlassian Marketplace that can be used with or without an agent with Jira Service Management Cloud, Data Center, or Server. The tool is designed to detect hardware and software connected to local networks and extract detailed information about each asset, which can then be imported into Assets in Jira Service Management (Atlassian Security, NVD).

Technical details

The vulnerability has a CVSS Score of 7.2 (High) with the vector string CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H. It allows an authenticated attacker to modify the actions taken by a system call, requiring no user interaction. The vulnerability is classified as an Injection type vulnerability (CWE-94) (Atlassian JIRA).

Impact

The vulnerability has high impact on confidentiality, integrity, and availability of the system. When successfully exploited, it allows authenticated attackers to modify system call actions, potentially compromising the security of the affected system (NVD).

Mitigation and workarounds

Atlassian recommends that Assets Discovery customers upgrade to version 7.0.0 or patch to version 6.2.1. The latest version can be downloaded from the Atlassian Marketplace. There is no need to upgrade the Jira Service Management product itself, only the Assets Discovery application and agents need to be updated (Atlassian Release Notes).

Additional resources


SourceThis report was generated using AI

Related Jira Assets Discovery Data Center vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-22523HIGH8.8
  • Jira Assets Discovery CloudJira Assets Discovery Cloud
  • cpe:2.3:a:atlassian:assets_discovery_data_center
NoYesDec 06, 2023
CVE-2024-21682HIGH7.2
  • Jira Assets Discovery Data CenterJira Assets Discovery Data Center
  • cpe:2.3:a:atlassian:assets_discovery_data_center
NoYesFeb 20, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management