cbcvebase.
CVE-2017-8907
published 2017-06-14

CVE-2017-8907: Atlassian Bamboo 5.x before 5.15.7 and 6.x before 6.0.1 did not correctly check if a user creating a deployment project had the edit permission and therefore…

PriorityP351high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.64%
73.7th percentile
Atlassian Bamboo 5.x before 5.15.7 and 6.x before 6.0.1 did not correctly check if a user creating a deployment project had the edit permission and therefore the rights to do so. An attacker who can login to Bamboo as a user without the edit permission for deployment projects is able to use this vulnerability, provided there is an existing plan with a green build, to create a deployment project and execute arbitrary code on an available Bamboo Agent. By default a local agent is enabled; this means that code execution can occur on the system hosting Bamboo as the user running Bamboo.

Affected

51 ranges· showing 25
VendorProductVersion rangeFixed in
atlassianatlassian_bamboo
atlassianatlassian_bamboo
atlassianbamboo
atlassianbamboo
atlassianbamboo
atlassianbamboo
atlassianbamboo
atlassianbamboo
atlassianbamboo
atlassianbamboo
atlassianbamboo
atlassianbamboo
atlassianbamboo
atlassianbamboo
atlassianbamboo
atlassianbamboo
atlassianbamboo
atlassianbamboo
atlassianbamboo
atlassianbamboo
atlassianbamboo
atlassianbamboo
atlassianbamboo
atlassianbamboo
atlassianbamboo

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.