First published: Sat Jan 23 2021(Updated: )
Affected versions of Atlassian Bamboo allow an unauthenticated remote attacker to view a stack trace that may reveal the path for the home directory in disk and if certain files exists on the tmp directory, via a Sensitive Data Exposure vulnerability in the /chart endpoint. The affected versions are before version 7.2.2.
Credit: security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Bamboo | <7.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-26067.
The severity of CVE-2021-26067 is medium with a CVSS score of 5.3.
Affected versions of Atlassian Bamboo are affected by CVE-2021-26067.
An unauthenticated remote attacker can exploit CVE-2021-26067 by viewing a stack trace that may reveal the path for the home directory in disk and the existence of certain files on the tmp directory, via a Sensitive Data Exposure vulnerability in the /chart endpoint.
To mitigate the vulnerability, it is recommended to upgrade to a version of Atlassian Bamboo that is not affected by CVE-2021-26067.