A privilege escalation flaw has been found, and is being actively exploited, in Atlassian Confluence, and has been assigned a bug alert severity of 'very high'. Atlassian recommends removing installations from the Intern... https://t.co/HPWAfkjXCW #BugAlertNotice
We will be leaving Twitter in the coming days and setting up on the https://t.co/hhgvAWw9DY Mastodon server. An announcement will be made when we're ready to transition. In the meantime, please consider joining our Slack. Spread the word π #BugAlertNews
https://t.co/WijkHz9h2j
@QLD_Comrade We have many RSS feeds; if you don't wish to be alerted for dev or test notices, you do not have to subscribe to those categories. I would not recommend subscribing to the 'all' feed. See docs at
https://t.co/RECWUDZ3d7
This is a test notice, which you have opted in to. Bug Alert has completed integrating Twilio support for international calls and SMS. Save our phone number to your contacts! https://t.co/PKeud3SfFY #BugAlertNotice
We would greatly appreciate having as many testers as possible. Visit https://t.co/IQ3forAty2, sign up for the 'Test Notices' category; thanks in advance!
Calls & SMS will come from +1 (507) 668-8567 [+1 507 NOVULNS π] and you can remove any old numbers from your contacts list.
Grafana issue which, if exploited, could lead to privilege escalation to admin. Not in widespread enough use for a formal notice. https://t.co/d80CxNWpia
Bug Alert has also completed adding international call & SMS support, which will be tested today. Expand this Tweet for info.
tl;dr on the OpenSSL vuln: it seemed bad originally, but then OpenSSL realized it wasn't critical after all. Treat it like any other software flaw and follow your normal patching cycle. Unlikely to be exploited in real-world configurations.
On Tuesday Nov 1st between 9-11am EDT, a security fix will be released for a critical OpenSSL 3.0.x vuln. Ubuntu 22.04 & RHEL 9 impacted. Docker ubuntu:latest also impacted. Latest releases of Alpine/Debian/AL2 not impacted, they use 1.1.x lineage. Last critical (2016) was RCE.
Still lots of unwarranted panic on this CVE, which some people are referring to as #text4shell. It's clear that this vulnerability has a number of preconditions that are unlikely to be found in the real world. There is no cause for alarm.
Bug Alert is watching CVE-2022-42889 (RCE in Apache Commons Text v1.5 - v1.9) carefully. So far, not seeing much evidence that this is widely exploitable, but we'll fire off a notice if that changes.
Bug Alert is watching CVE-2022-42889 (RCE in Apache Commons Text v1.5 - v1.9) carefully. So far, not seeing much evidence that this is widely exploitable, but we'll fire off a notice if that changes.
Multiple Vulnerabilities have been disclosed in Atlassian Products. A hardcoded credential vulnerability in Questions for Confluence, and Servlet Filter Bypass Vulnerabilities have been found in multiple Atlassian produc... https://t.co/5K2hgTkZ62 #BugAlertNotice
The urgency around CVE-2022-2274 is not matching up with reality. The likelihood of being vulnerable in the real-world is catastrophically small. The industry is already suffering from RCE vuln fatigue, let's not make it worse.
@fakehackhistory Our project can help you get the vendors contacted as well as coordinate public disclosure. DMs open if you want assistance. Tweets by @MattsLifeBytes
Confluence PoCs are out and it's as trivial as it gets:
GET /%24%7B%40java.lang.Runtime%40getRuntime%28%29.exec%28%22touch%20/tmp/r7%22%29%7D/ HTTP/1.1
An unauthenticated remote code execution flaw has been found, and is being actively exploited, in Atlassian Confluence, and has been assigned a bug alert severity of 'very high'. Atlassian recommends removing installatio... https://t.co/YzOyDUR4zC #BugAlertNotice