QID 731338

QID 731338: Atlassian Bamboo Server and Data Center Multiple Security Vulnerabilities (BAM-21696, BAM-21697)

Atlassian Bamboo is a continuous integration (CI) and deployment server. Bamboo Data Center is a continuous delivery pipeline that offers resilience, reliability, and scalability for teams of any size.

CVE-2020-9493 and CVE-2022-23307: Apache Chainsaw is bundled with log4j 1.2.x, and is vulnerable to a deserialization flaw. A remote, unauthenticated attacker could exploit this to execute arbitrary code.
CVE-2022-23302: JMSSink is vulnerable to a deserialization flaw. A local attacker with privileges to update the Bamboo configuration can exploit this to execute arbitrary code.
CVE-2022-23305: JDBCAppender is vulnerable to a SQL injection flaw when configured to use the message converter. A remote, unauthenticated attacker can exploit this to execute arbitrary SQL queries.

Affected Bamboo Server and Data Center:
All versions prior to 8.1.4

QID Detection Logic:(Unauthenticated):
QID checks for the vulnerable versions of Atlassian Bamboo via GET login request.

QID Detection Logic:(Windows):
QID checks for the vulnerable versions of Atlassian Bamboo through the registry key.

Successful exploitation of this vulnerability may affect Confidentiality, Integrity, and Availability of the data.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 9 severity.
  • Solution
    The vendor has released a fix for this vulnerability. Refer to BAM-21696 and BAM-21697for updates pertaining to this vulnerability.

    CVEs related to QID 731338

    Software Advisories
    Advisory ID Software Component Link
    BAM-21696 URL Logo jira.atlassian.com/browse/BAM-21696
    BAM-21697 URL Logo jira.atlassian.com/browse/BAM-21697