QID 731325

QID 731325: Atlassian Bamboo Server and Data Center Information Exposure vulnerability (BAM-25152, BAM-25153)

Atlassian Bamboo is a continuous integration (CI) and deployment server. Bamboo Data Center is a continuous delivery pipeline that offers resilience, reliability, and scalability for teams of any size.

CVE-2021-46877,CVE-2022-42003: This Third-Party Dependency vulnerability, allows an unauthenticated attacker to expose assets in the environment susceptible to exploitation.

Affected Bamboo Server and Data Center:
from version 9.1.0 to 9.1.3
from version 9.2.1 to 9.2.4
from version 9.3.0 to 9.3.2.

QID Detection Logic:(Unauthenticated):
QID checks for the vulnerable versions of Atlassian Bamboo via GET login request.

QID Detection Logic:(Windows):
QID checks for the vulnerable versions of Atlassian Bamboo through the registry key.

Successful exploitation of this vulnerability allows unauthenticated attacker to expose assets in your environment.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    The vendor has released fix for this vulnerability. Refer to BAM-25152 and BAM-25153 for updates pertaining to this vulnerability.

    CVEs related to QID 731325

    Software Advisories
    Advisory ID Software Component Link
    BAM-25152 URL Logo jira.atlassian.com/browse/BAM-25152
    BAM-25153 URL Logo jira.atlassian.com/browse/BAM-25153