QID 731042
Date Published: 2023-12-22
QID 731042: Atlassian Bamboo Server and Data Center Remote Code Execution (RCE) Vulnerability (CVE-2023-46604)
Bamboo Server and Data Center is vulnerable to CVE-2023-22506 in which authenticated attacker to modify the actions taken by a system call and execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and no user interaction.
Affected Bamboo Server and Data Center:
Versions prior to 9.2.7, 9.3.5,9.4.1
QID Detection Logic:(Unauthenticated):
QID checks for the vulnerable versions of Atlassian Bamboo via GET login request.
THis vulnerability allows an authenticated attacker to modify the actions taken by a system call and execute arbitrary code.
Solution
Vendor has released fix to this issue. Refer to Bamboo Server and Data Center Download
Vendor References
- BAM-25444 -
jira.atlassian.com/browse/BAM-25444
CVEs related to QID 731042
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| BAM-25444 |
|