CVE-2024-21689
published 2024-08-20CVE-2024-21689: This High severity RCE (Remote Code Execution) vulnerability CVE-2024-21689 was introduced in versions 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0, and 9.6.0 of Bamboo…
PriorityP352high8CVSS 3.1
AVNACLPRLUIRSUCHIHAH
EPSS
2.48%
82.7th percentile
This High severity RCE (Remote Code Execution) vulnerability CVE-2024-21689 was introduced in versions 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0, and 9.6.0 of Bamboo Data Center and Server.
This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.6, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction.
Atlassian recommends that Bamboo Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:
Bamboo Data Center and Server 9.2: Upgrade to a release greater than or equal to 9.2.17
Bamboo Data Center and Server 9.6: Upgrade to a release greater than or equal to 9.6.5
See the release notes ([https://confluence.atlassian.com/bambooreleases/bamboo-release-notes-1189793869.html]). You can download the latest version of Bamboo Data Center and Server from the download center ([https://www.atlassian.com/software/bamboo/download-archives]).
This vulnerability was reported via our Bug Bounty program.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| atlassian | bamboo | >= 9.1.0 < 9.2.17 | 9.2.17 |
| atlassian | bamboo | >= 9.3.0 < 9.6.5 | 9.6.5 |
| atlassian | bamboo_data_center | — | — |
| atlassian | bamboo_data_center | — | — |
| atlassian | bamboo_data_center | — | — |
| atlassian | bamboo_data_center | — | — |
| atlassian | bamboo_data_center | — | — |
| atlassian | bamboo_data_center | — | — |
| atlassian | bamboo_server | — | — |
| atlassian | bamboo_server | — | — |
| atlassian | bamboo_server | — | — |
| atlassian | bamboo_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability affects authenticated users — monitor for unexpected code execution or process spawning from Bamboo Data Center/Server processes on affected versions (9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0, 9.6.0) ↗
- →Exploitation requires user interaction — monitor for social-engineering vectors targeting Bamboo users (e.g., malicious plan/build configurations or repository links) that could trigger code execution ↗
- ·CVE-2024-21689 only affects Bamboo Data Center and Server versions 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0, and 9.6.0. Fixed in 9.2.17+ and 9.6.5+. ↗
- ·Doc 2 describes a different CVE (CVE-2026-21570) and was not used for CVE-2024-21689 intel extraction. ↗
CVSS provenance
nvdv3.18.0HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv3.07.6HIGHCVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
2024-08-20
Published