Impact
This vulnerability is a high‑severity Remote Code Execution flaw identified in Atlassian Bamboo Data Center. According to the vendor description, an attacker who can authenticate to the instance can execute arbitrary code on the server. The weakness is classified as CWE‑94, which describes unsafe evaluation of code. Successful exploitation would compromise the integrity and confidentiality of the host and any dependent services, effectively giving the attacker full control of the system.
Affected Systems
Affected systems are Atlassian Bamboo Data Center across multiple major releases. The flaw exists in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 12.1.0. Atlassian recommends upgrading to the latest overall release, or for the specified lines, to 9.6.24 or newer, 10.2.16 or newer, or 12.1.3 or newer respectively.
Risk and Exploitability
The CVSS score is 8.6, indicating a high severity vulnerability. No EPSS score is provided, and the issue is not listed in the CISA KEV catalog. Exploitation requires valid Bamboo credentials or some form of authentication. Once authenticated, the attacker can run arbitrary code on the host. The combination of a high severity score and the authentication requirement signals a significant risk for impacted organizations.
OpenCVE Enrichment