We have identified and fixed a vulnerability in Bamboo that results from the way third-party XML parsers are used in Bamboo.
This vulnerability allows an attacker to:
- Execute denial of service attacks against the Bamboo server, and
- Read all local files readable to the system user under which Bamboo runs.
The attacker needs to have an account with the affected Bamboo server instance and be able to log in in order to execute the attack.
All versions of Bamboo up to and including 3.4.4 are affected.
Full details of the severity, risks and vulnerability can be found in the Bamboo Security Advisory 2012-05-17.