CVE-2023-22516

4 documents4 sources
Severity
8.8HIGH
EPSS
1.7%
top 17.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 21

Description

This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 8.1.0, 8.2.0, 9.0.0, 9.1.0, 9.2.0, and 9.3.0 of Bamboo Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.5, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires no user interaction. Atlassian recommends that Bamboo Data Center and Server customers u

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

CVEListV5atlassian/bamboo_data_center39 versions+38
CVEListV5atlassian/bamboo_server39 versions+38
NVDatlassian/bamboo8.1.09.2.7+1

🔴Vulnerability Details

2
GHSA
GHSA-xqv7-xc39-ph8v: This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 82023-11-21
CVEList
CVE-2023-22516: This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 82023-11-21

📋Vendor Advisories

1
Atlassian
CVE-2023-22516: RCE (Remote Code Execution) in Bamboo Data Center and Server2023-11-21
CVE-2023-22516 (HIGH CVSS 8.8) | This High severity RCE (Remote Code | cvebase.io