Certain versions of the Atlassian Companion App for MacOS were affected by a remote code execution vulnerability. An attacker could utilize WebSockets to bypass Atlassian Companion’s blocklist and MacOS Gatekeeper to allow execution of code.
No PoCs from references.
- https://github.com/ARPSyndicate/cve-scores
- https://github.com/imperva/CVE-2023-22524
- https://github.com/nomi-sec/PoC-in-GitHub
- https://github.com/ron-imperva/CVE-2023-22524