QID 731324
QID 731324: Atlassian Bamboo Server and Data Center Code Injection and Directory Traversal Vulnerability (BAM-21216)
Atlassian Bamboo is a continuous integration (CI) and deployment server. Bamboo Data Center is a continuous delivery pipeline that offers resilience, reliability, and scalability for teams of any size.
CVE-2017-1000487: This vulnerability allows unauthenticated remote attackers to inject code and XML as well as perform directory traversal via command injection
Affected Bamboo Server and Data Center:
All versions prior to 7.2.2
QID Detection Logic:(Unauthenticated):
QID checks for the vulnerable versions of Atlassian Bamboo via GET login request.
QID Detection Logic:(Windows):
QID checks for the vulnerable versions of Atlassian Bamboo through the registry key.
Note: This QID has been marked as potential because the vendor has provided a workaround and that is not possible to detect it in the system.
Successful exploitation of this vulnerability allows unauthenticated remote attackers to inject code and XML as well as perform directory traversal via command injection.
- BAM-21216 -
jira.atlassian.com/browse/BAM-21216
CVEs related to QID 731324
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| BAM-21216 |
|