PT-2017-18614 · Atlassian · Bamboo
Inhibitor181
+1
·
Published
2017-06-14
·
Updated
2024-10-16
·
CVE-2017-8907
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Atlassian Bamboo versions 5.x through 5.15.6
Atlassian Bamboo versions 6.x through 6.0.0
Description
The issue arises from incorrect permission checks for users creating deployment projects. An attacker with login access to Bamboo, but without edit permission for deployment projects, can exploit this to create a deployment project and execute arbitrary code on an available Bamboo Agent, given an existing plan with a green build. By default, a local agent is enabled, allowing code execution on the system hosting Bamboo as the user running Bamboo.
Recommendations
For Atlassian Bamboo versions 5.x through 5.15.6, update to version 5.15.7 or later.
For Atlassian Bamboo versions 6.x through 6.0.0, update to version 6.0.1 or later.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bamboo