Deployment Project Permissions Flaw in Atlassian Bamboo
CVE-2017-8907
8.8HIGH
Summary
Atlassian Bamboo versions 5.x prior to 5.15.7 and 6.x prior to 6.0.1 contain an improper authorization vulnerability. This flaw allows authenticated users lacking the necessary edit permissions for deployment projects to exploit the system. If such a user has access to an existing plan with a successful build, they can create a deployment project. This, in turn, enables them to execute arbitrary code on any Bamboo Agent that is available, as the default configuration allows for a local agent, leading to potential risks of compromise on the hosting system.
Affected Version(s)
Atlassian Bamboo 5.0.0 <= version < 5.15.7 < 5.0.0 version 5.15.7
Atlassian Bamboo 6.0.0 <= version < 6.0.1 < 6.0.0 version 6.0.1
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved