QID 730852
Date Published: 2023-07-25
QID 730852: Atlassian Bamboo Server and Data Center Remote Code Execution (RCE) Vulnerability (CVE-2023-22506)
Bamboo Server and Data Center is vulnerable to CVE-2023-22506 in which authenticated attacker to modify the actions taken by a system call and execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and no user interaction.
Affected Bamboo Server and Data Center:
Versions from 8.0.0 prior to 9.2.3, 9.3.1
QID Detection Logic:(Unauthenticated):
QID checks for the vulnerable versions of Atlassian Bamboo via GET login request.
THis vulnerability allows an authenticated attacker to modify the actions taken by a system call and execute arbitrary code.
Solution
Vendor has released fix to this issue. Refer to Bamboo Server and Data Center Download
Vendor References
- CVE-2023-22506 -
jira.atlassian.com/browse/BAM-22400
CVEs related to QID 730852
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2023-22506 |
|