PT-2018-9645 · Atlassian+2 · Bamboo Server+4

Gambler

·

Publicado

2018-04-11

·

Atualizado

2024-08-05

·

CVE-2018-10054

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: H2 versions 1.4.197 Datomic versions prior to 0.9.5697 Bamboo Data Center and Server versions 9.1.0 through 9.4.0
Description: The issue allows remote code execution because the CREATE ALIAS command can execute arbitrary Java code. This can be exploited by an authenticated attacker to expose assets in the environment, which has a high impact on confidentiality, integrity, and availability. The vendor's position is that H2 is not designed to be run outside of a secure environment.
Recommendations: For H2 version 1.4.197, consider disabling the CREATE ALIAS command until a patch is available. For Datomic versions prior to 0.9.5697, upgrade to version 0.9.5697 or later. For Bamboo Data Center and Server version 9.2, upgrade to a release greater than or equal to 9.2.8. For Bamboo Data Center and Server version 9.3, upgrade to a release greater than or equal to 9.3.6. For Bamboo Data Center and Server version 9.4, upgrade to a release greater than or equal to 9.4.2.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-10054
GHSA-9PF8-QQHM-7W64

Produtos afetados

Bamboo
Bamboo Server
Datomic
H2
Jira Service Management Server