CVE-2024-21689

CWE-94Code Injection3 documents3 sources
Severity
8.0HIGH
EPSS
42.4%
top 2.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 20

Description

This High severity RCE (Remote Code Execution) vulnerability CVE-2024-21689 was introduced in versions 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0, and 9.6.0 of Bamboo Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.6, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction. Atlassian recommends that Bamboo Data Center and Server

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:HExploitability: 2.1 | Impact: 5.9

Affected Packages3 packages

CVEListV5atlassian/bamboo_data_center6 versions+5
CVEListV5atlassian/bamboo_server4 versions+3
NVDatlassian/bamboo9.1.09.2.17+1

🔴Vulnerability Details

2
CVEList
CVE-2024-21689: This High severity RCE (Remote Code Execution) vulnerability CVE-2024-21689 was introduced in versions 92024-08-20
GHSA
GHSA-h63c-4f8g-75qg: This High severity RCE (Remote Code Execution) vulnerability CVE-2024-21689 was introduced in versions 92024-08-20
CVE-2024-21689 (HIGH CVSS 8) | This High severity RCE (Remote Code | cvebase.io