QID 731328

QID 731328: Atlassian Bamboo Server and Data Center Information Exposure Vulnerability (BAM-21215)

Atlassian Bamboo is a continuous integration (CI) and deployment server. Bamboo Data Center is a continuous delivery pipeline that offers resilience, reliability, and scalability for teams of any size.

CVE-2021-26067: Affected versions of Atlassian Bamboo allow an unauthenticated remote attacker to view a stack trace that may reveal the path for the home directory in disk and if certain files exists on the tmp directory, via a Sensitive Data Exposure vulnerability in the /chart endpoint.

Affected Bamboo Server and Data Center:
versions prior to 7.2.2

QID Detection Logic:(Unauthenticated):
QID checks for the vulnerable versions of Atlassian Bamboo via GET login request.

QID Detection Logic:(Windows):
QID checks for the vulnerable versions of Atlassian Bamboo through the registry key.

Successful exploitation of this vulnerability allow an unauthenticated remote attacker to view a stack trace that may reveal the path for the home directory in disk and if certain files exists on the tmp directory.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    The vendor has released fix for this vulnerability. Refer to BAM-21215 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 731328

    Software Advisories
    Advisory ID Software Component Link
    BAM-21215 URL Logo jira.atlassian.com/browse/BAM-21215