Remote Code Execution Vulnerability in Bamboo Data Center and Server by Atlassian
CVE-2023-22516
8.5HIGH
Key Information:
- Vendor
- Atlassian
- Vendor
- CVE Published:
- 21 November 2023
Summary
A Remote Code Execution vulnerability has been identified in Bamboo Data Center and Server versions 8.1.0 through 9.3.0, allowing authenticated attackers to execute arbitrary code without user interaction. This vulnerability poses significant risks, affecting confidentiality, integrity, and availability. It is crucial for users on affected versions to upgrade immediately to the latest release or a specified fixed version to mitigate potential exploitation. For guidance on upgrades, please refer to Atlassian's official documentation.
Affected Version(s)
Bamboo Data Center >= 8.1.0 < 8.1.0
Bamboo Data Center >= 8.1.1 >= 8.1.1
Bamboo Data Center >= 8.1.10 >= 8.1.10
References
CVSS V3.1
Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
a private user