Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2024-21682

CVE-2024-21682: Assets Discovery Data Center RCE Flaw

CVE-2024-21682 is a remote code execution injection flaw in Atlassian Assets Discovery Data Center affecting versions 1.0 through 6.2.0. This article covers the technical details, affected versions, security impact, and mitigation.

Published:

CVE-2024-21682 Overview

CVE-2024-21682 is a high-severity code injection vulnerability affecting Atlassian Assets Discovery versions 1.0 through 6.2.0. Assets Discovery is a network scanning tool distributed via the Atlassian Marketplace and used with Jira Service Management Cloud, Data Center, and Server to detect hardware and software assets on local networks.

The flaw allows an authenticated attacker to modify actions taken by a system call, resulting in high impact to confidentiality, integrity, and availability. Atlassian reported the issue through its Penetration Testing program and released fixed versions to address the flaw.

Critical Impact

An authenticated attacker can inject and execute unauthorized commands through the Assets Discovery component, compromising the underlying host and all discovered asset data.

Affected Products

  • Atlassian Assets Discovery 1.0 through 6.2.0 (all versions in this range)
  • Assets Discovery Data Center deployments
  • Assets Discovery instances integrated with Jira Service Management Cloud, Data Center, and Server

Discovery Timeline

  • 2024-02-20 - CVE-2024-21682 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2024-21682

Vulnerability Analysis

CVE-2024-21682 is classified under CWE-94: Improper Control of Generation of Code. The vulnerability resides in Assets Discovery, a network scanning tool used to enumerate hardware and software connected to a local network. Data collected by Assets Discovery flows into Jira Service Management for configuration management.

The injection flaw allows an authenticated attacker to influence the arguments or behavior of system calls executed by the Assets Discovery application. Because the tool interacts with operating system commands during scanning and asset ingestion, unsanitized input can be interpreted as executable code or command arguments. Successful exploitation impacts the host running Assets Discovery and any downstream Jira Service Management data it feeds.

Root Cause

The root cause is improper control over generated code passed to system calls. Assets Discovery does not fully sanitize or restrict attacker-controlled input before that input reaches a code or command execution sink. This allows an authenticated user to alter the intended semantics of the underlying system call.

Attack Vector

The attack vector is network-based and requires authentication with elevated privileges on the Assets Discovery instance. No user interaction is required. Atlassian has not published exploit details, and no public proof-of-concept is available at the time of writing.

Technical mechanics are described in the Atlassian security advisory and the Atlassian Jira ticket JSDSERVER-15067. No verified proof-of-concept code is available; refer to the vendor advisory for further technical detail.

Detection Methods for CVE-2024-21682

Indicators of Compromise

  • Unexpected child processes spawned by the Assets Discovery service or its Java runtime on scanner hosts.
  • Anomalous outbound connections from Assets Discovery agents to hosts outside the configured scan scope.
  • Modifications to Assets Discovery scan configurations, credentials, or job definitions by non-administrative accounts.

Detection Strategies

  • Audit Jira Service Management and Assets Discovery application logs for unusual scan job creation, edits, or execution by authenticated users.
  • Correlate process execution telemetry on Assets Discovery hosts with scheduled scan windows to identify command execution outside expected activity.
  • Monitor for shell interpreters (/bin/sh, bash, cmd.exe, powershell.exe) invoked as children of the Assets Discovery service account.

Monitoring Recommendations

  • Enable verbose audit logging for Assets Discovery administrative actions and forward logs to a centralized SIEM.
  • Alert on privilege changes and new administrative sessions on Jira Service Management tied to Assets Discovery configuration.
  • Track version and patch state of all Assets Discovery instances against the fixed release list.

How to Mitigate CVE-2024-21682

Immediate Actions Required

  • Upgrade Assets Discovery to the latest fixed version listed in the Atlassian release notes.
  • Restrict administrative access to Assets Discovery and Jira Service Management to a minimal set of trusted accounts.
  • Rotate credentials used by Assets Discovery scan agents if compromise is suspected.

Patch Information

Atlassian released fixed versions of Assets Discovery to address CVE-2024-21682. Cloud users receive fixes automatically. Data Center and Server operators should download the latest release from the Atlassian Marketplace app installation page and follow the vendor upgrade procedure. Details are documented in the Atlassian Assets Discovery guide.

Workarounds

  • If immediate patching is not possible, upgrade to one of the supported fixed versions specified by Atlassian rather than remaining on any 1.0 through 6.2.0 release.
  • Limit network reachability of the Assets Discovery management interface to trusted administrator networks only.
  • Reduce the number of accounts holding administrative privileges on Assets Discovery to shrink the authenticated attack surface.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.