PT-2018-16815 · Mozilla+2 · Mercurial+2
Zhang Tianqi
·
Publicado
2018-03-29
·
Atualizado
2018-04-24
·
CVE-2018-5224
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Bamboo versions 2.7.0 through 6.3.2
Bamboo versions 6.4.0
Description
The issue arises from Bamboo's failure to properly check if a configured Mercurial repository URI contains values that the Windows operating system may consider argument parameters. This allows an attacker with specific permissions to execute code of their choice on systems running a vulnerable version of Bamboo on the Windows operating system.
Recommendations
For Bamboo versions 2.7.0 through 6.3.2, update to version 6.3.3 or later.
For Bamboo version 6.4.0, update to version 6.4.1 or later.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Bamboo
Mercurial
Windows