Remote Code Execution Vulnerability in Bamboo Data Center and Server by Atlassian
CVE-2023-22516

8.5HIGH

Key Information:

Vendor
Atlassian
Vendor
CVE Published:
21 November 2023

Summary

A Remote Code Execution vulnerability has been identified in Bamboo Data Center and Server versions 8.1.0 through 9.3.0, allowing authenticated attackers to execute arbitrary code without user interaction. This vulnerability poses significant risks, affecting confidentiality, integrity, and availability. It is crucial for users on affected versions to upgrade immediately to the latest release or a specified fixed version to mitigate potential exploitation. For guidance on upgrades, please refer to Atlassian's official documentation.

Affected Version(s)

Bamboo Data Center >= 8.1.0 < 8.1.0

Bamboo Data Center >= 8.1.1 >= 8.1.1

Bamboo Data Center >= 8.1.10 >= 8.1.10

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

a private user
.