Lucene search

K
atlassianA3e6629b6e9dBAM-25386
HistoryNov 02, 2023 - 3:05 p.m.

Update ActiveMQ to fix CVE-2023-46604

2023-11-0215:05:16
a3e6629b6e9d
jira.atlassian.com
150
bamboo
activemq
cve-2023-46604
apache
rce
vulnerability
upgrade
firewall

CVSS3

10

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H

AI Score

9.4

Confidence

High

EPSS

0.971

Percentile

99.8%

h3. Issue Summary

Bamboo relies on ActiveMQ libraries version <= 5.16.6 or <=5.18.2 which are affected by [CVE-2023-46604|https://nvd.nist.gov/vuln/detail/CVE-2023-46604].

An official advisory has been released. Please check [CVE-2023-46604 - Apache ActiveMQ RCE Vulnerability impacts Bamboo Data Center and Server|https://jira.atlassian.com/browse/BAM-25444] and the [FAQ|https://confluence.atlassian.com/kb/faq-for-cve-2023-46604-1318881301.html] for details.
h3. Steps to Reproduce

On the Bamboo instance, validate the ActiveMQ library versions in {{{}<bamboo-install>/atlassian-bamboo/WEB-INF/lib{}}}:
{noformat}
$ ls -al /opt/atlassian/bamboo/atlassian-bamboo/WEB-INF/lib# ls | grep activemq-
activemq-broker-5.18.2.jar
activemq-client-5.18.2.jar
activemq-http-5.18.2.jar
activemq-jms-pool-5.18.2.jar
activemq-kahadb-store-5.18.2.jar
activemq-openwire-legacy-5.18.2.jar
activemq-pool-5.18.2.jar
activemq-protobuf-1.1.jar
activemq-ra-5.18.2.jar
activemq-spring-5.18.2.jar
{noformat}
h3. Expected Results

The updated ActiveMQ library version is >= 5.16.7 or >= 5.18.3
h3. Actual Results

The ActiveMQ library version is <= 5.16.6 or <=5.18.2
h3. Workaround

Make sure that Bamboo is behind a firewall/VPC and allows connections to its ActiveMQ broker port only from trusted Agents.

Affected configurations

Vulners
Node
atlassianbamboo_data_centerRange1.0.0
OR
atlassianbamboo_data_centerRange<9.2.7
OR
atlassianbamboo_data_centerRange<9.3.5
OR
atlassianbamboo_data_centerRange<9.4.1
VendorProductVersionCPE
atlassianbamboo_data_center*cpe:2.3:a:atlassian:bamboo_data_center:*:*:*:*:*:*:*:*

CVSS3

10

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H

AI Score

9.4

Confidence

High

EPSS

0.971

Percentile

99.8%