Record summary

CVE-2024-21689 has a selected CVSS score of 8.0 (high); EIP currently links 1 repository PoC.

Description

This High severity RCE (Remote Code Execution) vulnerability CVE-2024-21689  was introduced in versions 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0, and 9.6.0 of Bamboo Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.6, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction. Atlassian recommends that Bamboo Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Bamboo Data Center and Server 9.2: Upgrade to a release greater than or equal to 9.2.17 Bamboo Data Center and Server 9.6: Upgrade to a release greater than or equal to 9.6.5 See the release notes ([https://confluence.atlassian.com/bambooreleases/bamboo-release-notes-1189793869.html]). You can download the latest version of Bamboo Data Center and Server from the download center ([https://www.atlassian.com/software/bamboo/download-archives]). This vulnerability was reported via our Bug Bounty program.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 27, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unknown

CVE List9.6.0 to 9.6.4affected
9.5.0 to 9.5.4affected
9.4.0 to 9.4.4affected
9.3.0 to 9.3.6affected
9.2.1 to 9.2.16affected
9.1.0 to 9.1.3affected
9.6.5unaffected
9.2.17unaffected
9.6.0 to < 9.6.4affected
9.5.0 to < 9.5.4affected
9.4.0 to < 9.4.4affected
9.3.0 to < 9.3.6affected
Showing 12 of 14 version ranges

Default status: unknown

CVE List9.4.0 to 9.4.4affected
9.3.0 to 9.3.6affected
9.2.1 to 9.2.16affected
9.1.0 to 9.1.3affected
9.2.17unaffected
Before 9.4.4affected
9.3.0 to < 9.3.6affected
9.2.1 to < 9.2.16affected
9.1.0 to < 9.1.3affected

Proofs of concept

1

Repository PoCs

GitHubsalvadornakamura/CVE-2024-21689Repository PoCby salvadornakamuraStars: 2Not analyzed2 files

1.1 KiB

GitHub

PoC details

References

3