File Inclusion Vulnerability in Bamboo Data Center and Server by Atlassian
CVE-2024-21687

8.1HIGH

Key Information:

Vendor
Atlassian
Vendor
CVE Published:
16 July 2024

Badges

πŸ“° News Worthy

Summary

A file inclusion vulnerability was identified in versions 9.0.0 to 9.6.0 of Bamboo Data Center and Server. An authenticated attacker can exploit this vulnerability to manipulate the application into accessing and displaying the contents of local files on the server. The potential consequences include significant risks to confidentiality and integrity of sensitive data, while availability remains unaffected. No user interaction is needed for an attack to succeed. Atlassian advises users to promptly update to the latest version or to one of the mentioned supported fixed versions. Detailed upgrade instructions can be found in the Bamboo release notes and the official download center.

Affected Version(s)

Bamboo Data Center 9.6.0 to 9.6.3

Bamboo Data Center 9.5.0 to 9.5.4

Bamboo Data Center 9.4.0 to 9.4.4

News Articles

Atlassian Fixes Server and Data Center Flaws - Spiceworks

Atlassian has released security updates to patch critical vulnerabilities in its server and data center products. Find out more.

6 months ago

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • πŸ“°

    First article discovered by Spiceworks

  • Vulnerability published

Credit

Bug Bounty
.