cbcvebase.
CVE-2017-9514
published 2017-10-12

CVE-2017-9514: Bamboo before 6.0.5, 6.1.x before 6.1.4, and 6.2.x before 6.2.1 had a REST endpoint that parsed a YAML file and did not sufficiently restrict which classes…

PriorityP346high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
1.05%
60.3th percentile
Bamboo before 6.0.5, 6.1.x before 6.1.4, and 6.2.x before 6.2.1 had a REST endpoint that parsed a YAML file and did not sufficiently restrict which classes could be loaded. An attacker who can log in to Bamboo as a user is able to exploit this vulnerability to execute Java code of their choice on systems that have vulnerable versions of Bamboo.

Affected

11 ranges
VendorProductVersion rangeFixed in
atlassianbamboo
atlassianbamboo
atlassianbamboo
atlassianbamboo
atlassianbamboo
atlassianbamboo
atlassianbamboo
atlassianbamboo
atlassianbamboo
atlassianbamboo
atlassianbamboo

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.