CVE-2023-22523: Atlassian Assets Discovery Cloud
High severity, CVSS 8.8. EPSS: 11.1% chance of exploitation in the next 30 days.
This vulnerability, if exploited, allows an attacker to perform privileged RCE (Remote Code Execution) on machines with the Assets Discovery agent installed. The vulnerability exists between the Assets Discovery application (formerly known as Insight Discovery) and the Assets Discovery agent.
Affected products
- Atlassian Assets Discovery Cloud: from 1.0.0, before 3.2.0 (fixed in 3.2.0)
- Atlassian Assets Discovery Data Center: from 1.0.0, up to and including 3.1.11; from 6.0.0, before 6.2.0 (fixed in 6.2.0)
- Atlassian Assets Discovery Data Server: from 1.0.0, up to and including 3.1.11; from 6.0.0, before 6.2.0 (fixed in 6.2.0)
Published 2023-12-06. Last modified 2026-06-17.