Deployment Project Permissions Flaw in Atlassian Bamboo
CVE-2017-8907

8.8HIGH

Key Information:

Vendor
Atlassian
Vendor
CVE Published:
14 June 2017

Summary

Atlassian Bamboo versions 5.x prior to 5.15.7 and 6.x prior to 6.0.1 contain an improper authorization vulnerability. This flaw allows authenticated users lacking the necessary edit permissions for deployment projects to exploit the system. If such a user has access to an existing plan with a successful build, they can create a deployment project. This, in turn, enables them to execute arbitrary code on any Bamboo Agent that is available, as the default configuration allows for a local agent, leading to potential risks of compromise on the hosting system.

Affected Version(s)

Atlassian Bamboo 5.0.0 <= version < 5.15.7 < 5.0.0 version 5.15.7

Atlassian Bamboo 6.0.0 <= version < 6.0.1 < 6.0.0 version 6.0.1

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.