Are you in the loop? Keep up with the latest by making sure you're subscribed to Community Announcements. Just click Watch and select Articles.

×
Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in
Celebration

Earn badges and make progress

You're on your way to the next level! Join the Kudos program to earn points and save your progress.

Deleted user Avatar
Deleted user

Level 1: Seed

25 / 150 points

Next: Root

Avatar

1 badge earned

Collect

Participate in fun challenges

Challenges come and go, but your rewards stay with you. Do more to earn more!

Challenges
Coins

Gift kudos to your peers

What goes around comes around! Share the love by gifting kudos to your peers.

Recognition
Ribbon

Rise up in the ranks

Keep earning points to reach the top of the leaderboard. It resets every quarter so you always have a chance!

Leaderboard

Is atlassian-bamboo-agent-installer-8.0.4.jar class log4j 2.9.0 vulnerable to CVE-2021-44228

Edited

We had to extract the atlassian-bamboo-agent-installer-8.0.4.jar and to analyse for CVE-2021-44228 for our client. 

 

What we found was that log4j 2.9.0 is in the atlassian-bamboo-agent-installer-8.0.4.jar/classpath.zip, but apparently its not an issue per Nexus-IQ.

 

Any idea if atlassian will be updating the atlassian-bamboo-agent-installer-8.0.4.jar ? 

 

Below are the extracted findings of the bamboo agent installer jar

image.pngimage.png

 

1 answer

1 vote
Daniel Eads
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
Dec 13, 2021

Hi @Vincent ,

Please see the advisory we released today - Multiple Products Security Advisory - Log4j Vulnerable To Remote Code Execution - CVE-2021-44228 - for the specific information in regards to Bamboo.

Hi Daniel, 

 

Thanks for getting back to me. I've checked our bamboo server and it seems clean per the advisory. 

 

I'm actually asking for the bamboo agent which is not stated

Like Steffen Opel [Utoolity] likes this
Alexey Chystoprudov
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
Dec 14, 2021

Bamboo agents are not affected as well. Added it to advisory

Like Steffen Opel [Utoolity] likes this

Hi Alexey,

I still can't see any reference to Bamboo agents on the linked advisory?

Alexey Chystoprudov
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
Dec 17, 2021

Old version was cached, it should be visible now

Like Daniel Eads likes this

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events