Deployment Project Permissions Flaw in Atlassian Bamboo
CVE-2017-8907
8.8HIGH
What is CVE-2017-8907?
Atlassian Bamboo versions 5.x prior to 5.15.7 and 6.x prior to 6.0.1 contain an improper authorization vulnerability. This flaw allows authenticated users lacking the necessary edit permissions for deployment projects to exploit the system. If such a user has access to an existing plan with a successful build, they can create a deployment project. This, in turn, enables them to execute arbitrary code on any Bamboo Agent that is available, as the default configuration allows for a local agent, leading to potential risks of compromise on the hosting system.
Affected Version(s)
Atlassian Bamboo 5.0.0 <= version < 5.15.7 < 5.0.0 version 5.15.7
Atlassian Bamboo 6.0.0 <= version < 6.0.1 < 6.0.0 version 6.0.1