← Back

CVE-2018-5224

nvd nist
Published: Mar 29, 2018Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

Bamboo did not correctly check if a configured Mercurial repository URI contained values that the Windows operating system may consider argument parameters. An attacker who has permission to create a repository in Bamboo, edit an existing plan in Bamboo that has a non-linked Mercurial repository, or create a plan in Bamboo either globally or in a project using Bamboo Specs can can execute code of their choice on systems that run a vulnerable version of Bamboo on the Windows operating system. All versions of Bamboo starting with 2.7.0 before 6.3.3 (the fixed version for 6.3.x) and from version 6.4.0 before 6.4.1 (the fixed version for 6.4.x) running on the Windows operating system are affected by this vulnerability.

Affected (2)

Products: Atlassian: Bamboo
1 product
Bamboo
Configuration A
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Atlassian
From 2.7.0 to 6.3.3
From 6.4.0 to 6.4.1
Running on/withPlatform Versions
Microsoft
Windows
All versions

References (6)

Source: security@atlassian.com
Third Party AdvisoryVDB Entry
Source: security@atlassian.com
MitigationVendor Advisory
Source: security@atlassian.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.