CVE-2017-8907

8.8HIGH

Key Information:

Vendor
Atlassian
Vendor
CVE Published:
14 June 2017

Summary

Atlassian Bamboo 5.x before 5.15.7 and 6.x before 6.0.1 did not correctly check if a user creating a deployment project had the edit permission and therefore the rights to do so. An attacker who can login to Bamboo as a user without the edit permission for deployment projects is able to use this vulnerability, provided there is an existing plan with a green build, to create a deployment project and execute arbitrary code on an available Bamboo Agent. By default a local agent is enabled; this means that code execution can occur on the system hosting Bamboo as the user running Bamboo.

Affected Version(s)

Atlassian Bamboo 5.0.0 <= version < 5.15.7 < 5.0.0 version 5.15.7

Atlassian Bamboo 6.0.0 <= version < 6.0.1 < 6.0.0 version 6.0.1

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.