QID 730852

Date Published: 2023-07-25

QID 730852: Atlassian Bamboo Server and Data Center Remote Code Execution (RCE) Vulnerability (CVE-2023-22506)

Bamboo Server and Data Center is vulnerable to CVE-2023-22506 in which authenticated attacker to modify the actions taken by a system call and execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and no user interaction.

Affected Bamboo Server and Data Center:
Versions from 8.0.0 prior to 9.2.3, 9.3.1

QID Detection Logic:(Unauthenticated):
QID checks for the vulnerable versions of Atlassian Bamboo via GET login request.

THis vulnerability allows an authenticated attacker to modify the actions taken by a system call and execute arbitrary code.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Medium - 5.1 severity.
  • Solution
    Vendor has released fix to this issue. Refer to Bamboo Server and Data Center Download
    Vendor References

    CVEs related to QID 730852

    Software Advisories
    Advisory ID Software Component Link
    CVE-2023-22506 URL Logo jira.atlassian.com/browse/BAM-22400