We have identified and fixed a vulnerability in Bamboo that results from the way third-party XML parsers are used in Bamboo.

      This vulnerability allows an attacker to:

      • Execute denial of service attacks against the Bamboo server, and
      • Read all local files readable to the system user under which Bamboo runs.

      The attacker needs to have an account with the affected Bamboo server instance and be able to log in in order to execute the attack.

      All versions of Bamboo up to and including 3.4.4 are affected.

      Full details of the severity, risks and vulnerability can be found in the Bamboo Security Advisory 2012-05-17.

            [BAM-11316] Bamboo XML Vulnerability

            VitalyA added a comment - - edited

            Installing the patch: (we recommend upgrading instead of patching)

            1. Download file http://www.atlassian.com/software/bamboo/downloads/binary/patch-BAM11316-3.2-atlassian-bundled-plugins.zip
            2. Rename the file to atlassian-bundled-plugins.zip
            3. Stop Bamboo.
            4. Make a backup of the <bamboo_install_dir> directory.
            5. Copy atlassian-bundled-plugins.zip into webapp/WEB-INF/classes in the <bamboo_install_dir>, to replace the existing file of the same name.
            6. Restart Bamboo.

            VitalyA added a comment - - edited Installing the patch: (we recommend upgrading instead of patching) Download file http://www.atlassian.com/software/bamboo/downloads/binary/patch-BAM11316-3.2-atlassian-bundled-plugins.zip Rename the file to atlassian-bundled-plugins.zip Stop Bamboo. Make a backup of the <bamboo_install_dir> directory. Copy atlassian-bundled-plugins.zip into webapp/WEB-INF/classes in the <bamboo_install_dir>, to replace the existing file of the same name. Restart Bamboo.

              vosipov VitalyA
              pwatson paulwatson (Inactive)
              Affected customers:
              0 This affects my team
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: