QID 731322

QID 731322: Atlassian Bamboo Server and Data Center Information Exposure Vulnerability (BAM-22479, BAM-22601)

Atlassian Bamboo is a continuous integration (CI) and deployment server. Bamboo Data Center is a continuous delivery pipeline that offers resilience, reliability, and scalability for teams of any size.

CVE-2023-28709: This Third-Party Dependency vulnerability, allows an attacker to expose assets in your environment susceptible to exploitation.

Affected Bamboo Server and Data Center:
from 8.1.12 to 9.2.3.
from 9.2.0 to 9.2.3.
from 9.3.0 to prior to 9.3.1

QID Detection Logic:(Unauthenticated):
QID checks for the vulnerable versions of Atlassian Bamboo via GET login request.

QID Detection Logic:(Windows):
QID checks for the vulnerable versions of Atlassian Bamboo through the registry key.

Successful exploitation of this vulnerability allows unauthenticated attacker to expose assets in your environment.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    The vendor has released fix for this vulnerability. Refer to BAM-22479 and BAM-22601for updates pertaining to this vulnerability.

    CVEs related to QID 731322

    Software Advisories
    Advisory ID Software Component Link
    BAM-22479 URL Logo jira.atlassian.com/browse/BAM-22479
    BAM-22601 URL Logo jira.atlassian.com/browse/BAM-22601