Impact
This vulnerability is an Improper Authorization flaw in Atlassian Bamboo Data Center versions 10 through 12. An attacker with valid credentials can elevate privileges to access resources or functions not intended for them. The flaw could allow exposure of sensitive information and, in some scenarios, enable execution of arbitrary code. With a CVSS score of 7.6, the issue is classified as high severity.
Affected Systems
Affected products include Atlassian Bamboo Data Center, specifically versions 10.0.0, 10.1.0, 10.2.0, 11.0.0, 12.0.0, and 12.1.0. Atlassian recommends upgrading to a release that is greater than or equal to 10.2.22 for Bamboo 10.2 or greater than or equal to 12.1.10 for Bamboo 12.1, or to the latest available release.
Risk and Exploitability
It is exploitable only by an authenticated user, so it requires a valid login. No information indicates availability of remote exploitation tools or existing public exploits. The EPSS score is indicated as < 1%, implying a very low exploitation probability, and the issue is not listed in CISA’s KEV catalog. The CVSS score of 7.6 reflects a high risk of unauthorized data access or code execution, but the attack vector is not remotely exploitable without prior authentication. Overall, the threat remains significant for organizations that cannot promptly apply the recommended patch.
OpenCVE Enrichment