CVE-2015-8360Improper Input Validation in Atlassian Bamboo

Severity
9.8CRITICALNVD
EPSS
1.2%
top 21.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 8
Latest updateMay 14

Description

An unspecified resource in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 allows remote attackers to execute arbitrary Java code via serialized data to the JMS port.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

NVDatlassian/bamboo87 versions+86

Patches

🔴Vulnerability Details

2
GHSA
GHSA-rw94-pr63-5frw: An unspecified resource in Atlassian Bamboo before 52022-05-14
CVEList
CVE-2015-8360: An unspecified resource in Atlassian Bamboo before 52016-02-08
CVE-2015-8360 — Improper Input Validation in Atlassian | cvebase