-
Type:
Public Security Vulnerability
-
Resolution: Fixed
-
Priority:
Low
-
Affects Version/s: 8.0.0, 8.0.1, 8.0.2, 8.0.3, 8.1.1, 8.0.4, 8.0.5, 8.1.2, 8.0.6, 8.1.3
-
Component/s: None
-
8.1
-
High
-
CVE-2020-9493
The version of log4j used by the Bamboo remote agent has been updated from version 1.2.7-atlassian-15 to 1.2.7-atlassian-16 to address the following vulnerabilities:
CVE-2020-9493 and CVE-2022-23307
Apache Chainsaw is bundled with log4j 1.2.x, and is vulnerable to a deserialization flaw. A remote, unauthenticated attacker could exploit this to execute arbitrary code. Please note that Chainsaw is a log viewer that is designed to be executed manually. It is not required by the Bamboo remote agent, nor is it executed by default, nor does Atlassian provide any documentation on using Chainsaw with the Bamboo remote agent. Atlassian has remediated this vulnerability by removing Chainsaw from the Atlassian version of log4j.
CVE-2022-23302
JMSSink is vulnerable to a deserialization flaw. A local attacker with privileges to update the Bamboo remote agent configuration can exploit this to execute arbitrary code. The Bamboo remote agent is not configured to use JMSSink by default, nor does Atlassian provide any documentation on using JMSSink with the Bamboo remote agent. Atlassian has remediated this vulnerability by removing JMSSink from the Atlassian version of log4j.
CVE-2022-23305
JDBCAppender is vulnerable to a SQL injection flaw when configured to use the message converter (%m). A remote, unauthenticated attacker can exploit this to execute arbitrary SQL queries. The Bamboo remote agent is not configured to use JDBCAppender by default, nor does Atlassian provide any documentation on using JDBCAppender with the Bamboo remote agent. Atlassian has remediated this vulnerability by removing JDBCAppender from the Atlassian version of log4j.
Affected versions of the Bamboo remote agent:
- Versions < 8.1.4
Fixed versions of the Bamboo remote agent:
- Versions 8.1.x >= 8.1.4
- Versions >= 8.2.0
- mentioned in
-
Page Loading...