PT-2018-16815 · Mozilla+2 · Mercurial+2
Zhang Tianqi
·
Published
2018-03-29
·
Updated
2018-04-24
·
CVE-2018-5224
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Bamboo versions 2.7.0 through 6.3.2
Bamboo versions 6.4.0
Description
The issue arises from Bamboo's failure to properly check if a configured Mercurial repository URI contains values that the Windows operating system may consider argument parameters. This allows an attacker with specific permissions to execute code of their choice on systems running a vulnerable version of Bamboo on the Windows operating system.
Recommendations
For Bamboo versions 2.7.0 through 6.3.2, update to version 6.3.3 or later.
For Bamboo version 6.4.0, update to version 6.4.1 or later.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bamboo
Mercurial
Windows