We have identified and fixed an information leakage vulnerability in Bamboo.
- An attacker will be able to view directory contents on the server if they are readable by the Bamboo user.
This issue is reported in our security advisory on this page:
http://confluence.atlassian.com/x/lwH6Dw
Form Name |
---|
[BAM-10031] Information leakage vulnerability
Workflow | Original: Bamboo Workflow 2016 v1 - Restricted [ 1439174 ] | New: JAC Bug Workflow v3 [ 3378226 ] |
Status | Original: Resolved [ 5 ] | New: Closed [ 6 ] |
Workflow | Original: Bamboo Workflow 2016 v1 [ 1413548 ] | New: Bamboo Workflow 2016 v1 - Restricted [ 1439174 ] |
Workflow | Original: Bamboo Workflow 2014 v2 [ 614718 ] | New: Bamboo Workflow 2016 v1 [ 1413548 ] |
Workflow | Original: Bamboo Workflow 2014 [ 599960 ] | New: Bamboo Workflow 2014 v2 [ 614718 ] |
Workflow | Original: Bamboo Workflow 2010 [ 351518 ] | New: Bamboo Workflow 2014 [ 599960 ] |
Security | Original: Reporters and Developers [ 10070 ] |
Description |
Original:
We have identified and fixed an information leakage vulnerability in Bamboo.
* An attacker might take advantage of the vulnerability to view directories that should be hidden from them. This issue is reported in our security advisory on this page: http://confluence.atlassian.com/x/lwH6Dw You can read more about shell injection attacks at cgisecurity, CERT and other places on the web: * http://www.cgisecurity.com/xss-faq.html * http://www.cert.org/advisories/CA-2000-02.html |
New:
We have identified and fixed an information leakage vulnerability in Bamboo.
* An attacker will be able to view directory contents on the server if they are readable by the Bamboo user. This issue is reported in our security advisory on this page: http://confluence.atlassian.com/x/lwH6Dw |
Resolution | New: Fixed [ 1 ] | |
Status | Original: Open [ 1 ] | New: Resolved [ 5 ] |
Link | New: This issue relates to BAM-9668 [ BAM-9668 ] |