QID 731338
QID 731338: Atlassian Bamboo Server and Data Center Multiple Security Vulnerabilities (BAM-21696, BAM-21697)
Atlassian Bamboo is a continuous integration (CI) and deployment server. Bamboo Data Center is a continuous delivery pipeline that offers resilience, reliability, and scalability for teams of any size.
CVE-2020-9493 and CVE-2022-23307: Apache Chainsaw is bundled with log4j 1.2.x, and is vulnerable to a deserialization flaw. A remote, unauthenticated attacker could exploit this to execute arbitrary code.
CVE-2022-23302: JMSSink is vulnerable to a deserialization flaw. A local attacker with privileges to update the Bamboo configuration can exploit this to execute arbitrary code.
CVE-2022-23305: JDBCAppender is vulnerable to a SQL injection flaw when configured to use the message converter. A remote, unauthenticated attacker can exploit this to execute arbitrary SQL queries.
Affected Bamboo Server and Data Center:
All versions prior to 8.1.4
QID Detection Logic:(Unauthenticated):
QID checks for the vulnerable versions of Atlassian Bamboo via GET login request.
QID Detection Logic:(Windows):
QID checks for the vulnerable versions of Atlassian Bamboo through the registry key.
Successful exploitation of this vulnerability may affect Confidentiality, Integrity, and Availability of the data.
- BAM-21696 -
jira.atlassian.com/browse/BAM-21696 - BAM-21697 -
jira.atlassian.com/browse/BAM-21697
CVEs related to QID 731338
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| BAM-21696 |
|
||
| BAM-21697 |
|