Hi All
According to this report there is a whole load of Atlassian products with security flaws, which are used in a lot of organisations these days.
Regards
Caute_Cautim
If you believe you have found a security issue that meets Atlassian’s definition of a vulnerability, please submit the report to our security team via one of the methods below: Only vulnerabilities submitted through our bug bounty program are eligible to receive a bounty payment. Please include the following information in your report: My HT Space
At first blush, three observations:
Still, all of this seems more proof of concept (maybe I missed something), but seems like CloudSek hacked itself (using its own cookies). Fundamentally, the issue is is there anything in these Atlassian applications that give up their cookies? I don't see that reported (although, apparently Atlassian cookies can be found for sale) While it is true that if someone gets their hands on a device, they then can get access to someone's cookies, if they have that kind of access, they can also get at password managers and the like. It's kind of game-over at that point anyway. I don't know if this all warrants alarm, but there certainly seem to be teachable and fixable moments here.