This High severity File Inclusion vulnerability was introduced in versions 9.0.0, 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0 and 9.6.0 of Bamboo Data Center and Server.
This File Inclusion vulnerability, with a CVSS Score of 8.1, allows an authenticated attacker to get the application to display the contents of a local file, or execute a different files already stored locally on the server which has high impact to confidentiality, high impact to integrity, no impact to availability, and requires no user interaction.
Atlassian recommends that Bamboo Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions listed on this CVE
See the release notes (https://confluence.atlassian.com/bambooreleases/bamboo-release-notes-1189793869.html). You can download the latest version of Bamboo Data Center and Server from the download center (https://www.atlassian.com/software/bamboo/download-archives).
This vulnerability was reported via our Bug Bounty program.
References
Link | Resource |
---|---|
https://confluence.atlassian.com/pages/viewpage.action?pageId=1417150917 | Vendor Advisory |
https://jira.atlassian.com/browse/BAM-25822 | Vendor Advisory |
https://confluence.atlassian.com/pages/viewpage.action?pageId=1417150917 | Vendor Advisory |
https://jira.atlassian.com/browse/BAM-25822 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
14 Mar 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-98 |
20 Feb 2025, 15:20
Type | Values Removed | Values Added |
---|---|---|
References | () https://confluence.atlassian.com/pages/viewpage.action?pageId=1417150917 - Vendor Advisory | |
References | () https://jira.atlassian.com/browse/BAM-25822 - Vendor Advisory | |
CWE | NVD-CWE-noinfo | |
CPE | cpe:2.3:a:atlassian:bamboo:*:*:*:*:*:*:*:* | |
First Time |
Atlassian
Atlassian bamboo |
21 Nov 2024, 08:54
Type | Values Removed | Values Added |
---|---|---|
References | () https://confluence.atlassian.com/pages/viewpage.action?pageId=1417150917 - | |
References | () https://jira.atlassian.com/browse/BAM-25822 - |
24 Oct 2024, 20:35
Type | Values Removed | Values Added |
---|---|---|
CWE |
01 Aug 2024, 13:46
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-98 |
17 Jul 2024, 13:34
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
16 Jul 2024, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-07-16 21:15
Updated : 2025-03-14 16:15
NVD link : CVE-2024-21687
Mitre link : CVE-2024-21687
CVE.ORG link : CVE-2024-21687
JSON object : View
Products Affected
atlassian
- bamboo
CWE
NVD-CWE-noinfo
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')