QID 731042

Date Published: 2023-12-22

QID 731042: Atlassian Bamboo Server and Data Center Remote Code Execution (RCE) Vulnerability (CVE-2023-46604)

Bamboo Server and Data Center is vulnerable to CVE-2023-22506 in which authenticated attacker to modify the actions taken by a system call and execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and no user interaction.

Affected Bamboo Server and Data Center:
Versions prior to 9.2.7, 9.3.5,9.4.1

QID Detection Logic:(Unauthenticated):
QID checks for the vulnerable versions of Atlassian Bamboo via GET login request.

THis vulnerability allows an authenticated attacker to modify the actions taken by a system call and execute arbitrary code.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Medium - 5.1 severity.
  • Solution
    Vendor has released fix to this issue. Refer to Bamboo Server and Data Center Download
    Vendor References

    CVEs related to QID 731042

    Software Advisories
    Advisory ID Software Component Link
    BAM-25444 URL Logo jira.atlassian.com/browse/BAM-25444