Atlassian uncovers vulnerability with exposed private certificate key

By on
Atlassian uncovers vulnerability with exposed private certificate key

Atlassian has confirmed a vulnerability in its Confluence team collaboration software is legitimate, which has since been resolved.

First reported by The Register, the issue was inadvertently disclosed on Twitter by SwiftOnSecurity, with a screenshot of an Atlassian domain (https://atlassian-domain-for-localhost-connections-only.com).

According to Atlassian's Confluence Support page, the domain resolves to a local server with a common SSL certificate for its Confluence cloud service, to enable Atlassian’s Companion app to edit files in a preferred local application and save files back to Confluence.

The exposed SSL key could potentially be used by an attacker to redirect app traffic to a malicious site.

Responding to SwiftOnSecurity’s tweet, Google's Tavis Ormandy said the private key could be stolen and an attacker could resolve a domain to a different one other than “localhost”.

"We are aware of this issue and are actively working on it. We have requested that the certificate be revoked, and we're evaluating whether other technical solutions are required to protect our customers," an Atlassian spokesperson told CRN.

Apart from Ormandy, the tweet caught the attention of other security researchers, one of which pointed out a similarity to the server scheme that IBM's Aspera plugin client uses, “local.connectme.us”, for client-server communication.

Ormandy remarked that the Aspera issue could be “way, way worse”. “There's a pre-generated CA certificate and a private key, if they add that to the system store, they're effectively disabling SSL. I would consider that *critical*,” his tweet read.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © CRN Australia. All rights reserved.
Tags:

Most Read Articles

You must be a registered member of CRN to post a comment.
| Register

Poll

What will be your biggest business challenge for 2020?
Slow economic growth and its impact on customers
Transitioning to an MSP model
Finding and retaining skilled staff
Finding time to work ON the business as well as IN it
No challenge: 2020 will be non-stop unicorns, rainbows and fun!
View poll archive

Log In

Username / Email:
Password:
  |  Forgot your password?