Uploaded image for project: 'Bamboo Data Center'
  1. Bamboo Data Center
  2. BAM-25444

Apache ActiveMQ RCE Vulnerability impacts Bamboo Data Center and Server - CVE-2023-46604

XMLWordPrintable

    • Icon: Public Security Vulnerability Public Security Vulnerability
    • Resolution: Fixed
    • Icon: Highest Highest
    • 9.2.7, 9.3.5, 9.4.1
    • 1.0.0
    • None
    • None

      Summary of Vulnerability

      Bamboo utilizes a third-party library ActiveMQ as part of its core services. Apache Active MQ has published a vulnerability (CVE-2023-46604) that allows Remote Code Execution (RCE). Because of the high severity of this Active MQ CVE, in the abundance of caution, we are publishing this advisory ahead of our regular schedule of advisories.

      This critical severity RCE (Remote Code Execution) vulnerability known as CVE-2023-46604 affects all versions prior to the listed fix versions of Bamboo Data Center and Server. Versions outside of the support window (i.e. versions that have reached End of Life) may also be affected, so Atlassian recommends you upgrade to a fixed LTS version or later.

      Affected Versions

      Product Affected Versions
      Bamboo Data Center
      Bamboo Server
      All versions are affected

      Fixed Versions

      Product Fixed Versions
      Bamboo Data Center
      Bamboo Server
      • 9.2.7 or later
      • 9.3.5 or later
      • 9.4.1 or later

      What You Need to Do

      Atlassian recommends that you upgrade your instance to one of the versions listed in the “Fixed Versions” table section of this ticket. For full descriptions of the above versions of Bamboo Data Center and Server, see the release notes. You can download the latest version of Bamboo Data Center and Server from the download center.

       

      For additional details, please see full advisory or the FAQ.

              Unassigned Unassigned
              e224d63853a5 Arshita Sandhiparthi
              Votes:
              0 Vote for this issue
              Watchers:
              11 Start watching this issue

                Created:
                Updated:
                Resolved: