VDB

CVE-2023-46604

CVE-2023-46604 PUBLISHED KEV CVSS 10 CRITICAL

h2. Summary of Vulnerability Bamboo utilizes a third-party library ActiveMQ as part of its core services. Apache Active MQ has published a vulnerability (CVE-2023-46604) that allows Remote Code Execution (RCE). Because of the high severity of this Active MQ CVE, in the abundance of caution, we are publishing this advisory ahead of our regular schedule of advisories. This critical severity RCE (Remote Code Execution) vulnerability known as CVE-2023-46604 affects all versions prior to the listed fix versions of Bamboo Data Center and Server. Versions outside of the support window (i.e. versions that have reached End of Life) may also be affected, so Atlassian recommends you upgrade to a fixed LTS version or later. h2. Affected Versions ||Product||Affected Versions|| |Bamboo Data Center Bamboo Server|All versions are affected| h2. Fixed Versions ||Product||Fixed Versions|| |Bamboo Data Center Bamboo Server| - 9.2.7 or later - 9.3.5 or later - 9.4.1 or later| h2. What You Need to Do Atlassian recommends that you upgrade your instance to one of the versions listed in the “Fixed Versions” table section of this ticket. For full descriptions of the above versions of Bamboo Data Center and Server, see the [release notes|https://confluence.atlassian.com/bambooreleases/bamboo-release-notes-1189793869.html]. You can download the latest version of Bamboo Data Center and Server from the [download center|https://www.atlassian.com/software/bamboo/download-archives].   For additional details, please see full [advisory|https://confluence.atlassian.com/display/SECURITY/CVE-2023-46604+-+Apache+ActiveMQ+RCE+Vulnerability+impacts+Bamboo+Data+Center+and+Server] or the [FAQ|https://confluence.atlassian.com/display/KB/FAQ+for+CVE-2023-46604].

EPSS 99.72% · 100.0th percentile

Risk Scores

CVSS 3.0
10
EPSS Score
99.72%
100.0th percentile

Affected Products

VendorProductVersions
AtlassianBamboo Server
AtlassianBamboo Data Center

Timeline

  • CVE Published
  • Oct 26, 2023 VulnCheck XDB Entry
  • Oct 27, 2023 Metasploit Module
  • Oct 28, 2023 EPSS Score
  • Nov 1, 2023 PoC Published
  • Nov 2, 2023 CISA KEV Added
  • Nov 2, 2023 VulnCheck KEV Exploitation
  • Nov 2, 2023 PoC Published
  • Nov 2, 2023 Nuclei Template
  • Nov 2, 2023 Fix Commit
  • Nov 3, 2023 VulnCheck KEV Exploitation
  • Nov 3, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›