PT-2022-7267 · Atlassian · Bamboo+1

·

CVE-2022-4244

·

Published

2022-12-01

·

Updated

2024-10-10

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions codeplex-codehaus (affected versions not specified) Bamboo Data Center and Server versions 9.2.1 through 9.2.7
Description A flaw was found in codeplex-codehaus, allowing a directory traversal attack to access files and directories stored outside the intended folder. By manipulating files with ../ sequences and their variations or by using absolute file paths, it may be possible to access arbitrary files and directories stored on the file system, including application source code, configuration, and other critical system files.
Recommendations For Bamboo Data Center and Server versions 9.2.1 through 9.2.7, upgrade to a release greater than or equal to 9.2.8. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation. Avoid using absolute file paths in the affected API endpoints until the issue is resolved. Restrict access to the vulnerable module to minimize the risk of exploitation.

Exploit

Fix

DoS

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-01536
CVE-2022-4244
GHSA-G6PH-X5WF-G337

Affected Products

Bamboo
Bamboo Server