Skip to main content

Vendor/product archive

atlassian / bamboo CVEs

Beta · best-effort

24 CVEs tagged to atlassian / bamboo8 Critical, 10 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2024-21689

Published Aug 20, 2024

This High severity RCE (Remote Code Execution) vulnerability CVE-2024-21689  was introduced in versions 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0, and 9.6.0 of Bamboo Data Center and Serv…

CVSS 8.0 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-21687

Published Jul 16, 2024

This High severity File Inclusion vulnerability was introduced in versions 9.0.0, 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0 and 9.6.0 of Bamboo Data Center and Server. This File Inclusio…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-22516

Published Nov 21, 2023

This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 8.1.0, 8.2.0, 9.0.0, 9.1.0, 9.2.0, and 9.3.0 of Bamboo Data Center and Server. This RCE…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-26137

Published Jul 20, 2022

A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5

CVE-2022-26136

Published Jul 20, 2022

A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2021-26067

Published Jan 28, 2021

Affected versions of Atlassian Bamboo allow an unauthenticated remote attacker to view a stack trace that may reveal the path for the home directory in disk and if certain files e…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-5224

Published Mar 29, 2018

Bamboo did not correctly check if a configured Mercurial repository URI contained values that the Windows operating system may consider argument parameters. An attacker who has pe…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-18082

Published Feb 2, 2018

The plan configure branches resource in Atlassian Bamboo before version 6.2.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulne…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18081

Published Feb 2, 2018

The signupUser resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability thro…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18080

Published Feb 2, 2018

The saveConfigureSecurity resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to modify security settings via a Cross-site request forgery (CSRF) vulnerabili…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-18042

Published Feb 2, 2018

The update user administration resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to modify user data including passwords via a Cross-site request forgery (…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-18041

Published Feb 2, 2018

The viewDeploymentVersionJiraIssuesDialog resource in Atlassian Bamboo before version 6.2.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripti…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18040

Published Feb 2, 2018

The viewDeploymentVersionCommits resource in Atlassian Bamboo before version 6.2.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS)…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14590

Published Dec 13, 2017

Bamboo did not check that the name of a branch in a Mercurial repository contained argument parameters. An attacker who has permission to create a repository in Bamboo, edit an ex…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-14589

Published Dec 13, 2017

It was possible for double OGNL evaluation in FreeMarker templates through Struts FreeMarker tags to occur. An attacker who has restricted administration rights to Bamboo or who h…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-9514

Published Oct 12, 2017

Bamboo before 6.0.5, 6.1.x before 6.1.4, and 6.2.x before 6.2.1 had a REST endpoint that parsed a YAML file and did not sufficiently restrict which classes could be loaded. An att…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-6576

Published Oct 3, 2017

Bamboo 2.2 before 5.8.5 and 5.9.x before 5.9.7 allows remote attackers with access to the Bamboo web interface to execute arbitrary Java code via an unspecified resource.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-8907

Published Jun 14, 2017

Atlassian Bamboo 5.x before 5.15.7 and 6.x before 6.0.1 did not correctly check if a user creating a deployment project had the edit permission and therefore the rights to do so.…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-5229

Published Aug 2, 2016

Atlassian Bamboo before 5.11.4.1 and 5.12.x before 5.12.3.1 does not properly restrict permitted deserialized classes, which allows remote attackers to execute arbitrary code via…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-8361

Published Feb 8, 2016

Multiple unspecified services in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 do not require authentication, which allows remote attackers to obtain sensitive informatio…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-8360

Published Feb 8, 2016

An unspecified resource in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 allows remote attackers to execute arbitrary Java code via serialized data to the JMS port.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-9757

Published Feb 8, 2016

The Ignite Realtime Smack XMPP API, as used in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0, allows remote configured XMPP servers to execute arbitrary Java code via ser…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-24 of 24 CVEsPage 1 of 1