Atlassian Bamboo vulnerabilities

24 known vulnerabilities affecting atlassian/bamboo.

Total CVEs
24
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH10MEDIUM6

Vulnerabilities

Page 1 of 2
CVE-2024-21689HIGHCVSS 8.0≥ 9.1.0, < 9.2.17≥ 9.3.0, < 9.6.52024-08-20
CVE-2024-21689 [HIGH] CWE-94 CVE-2024-21689: This High severity RCE (Remote Code Execution) vulnerability CVE-2024-21689  was introduced in versi This High severity RCE (Remote Code Execution) vulnerability CVE-2024-21689 was introduced in versions 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0, and 9.6.0 of Bamboo Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.6, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiali
nvd
CVE-2024-21687HIGHCVSS 8.1≥ 9.0.0, ≤ 9.0.4≥ 9.1.0, ≤ 9.1.3+5 more2024-07-16
CVE-2024-21687 [HIGH] CWE-98 CVE-2024-21687: This High severity File Inclusion vulnerability was introduced in versions 9.0.0, 9.1.0, 9.2.0, 9.3. This High severity File Inclusion vulnerability was introduced in versions 9.0.0, 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0 and 9.6.0 of Bamboo Data Center and Server. This File Inclusion vulnerability, with a CVSS Score of 8.1, allows an authenticated attacker to get the application to display the contents of a local file, or execute a different files alread
nvd
CVE-2023-22516HIGHCVSS 8.8≥ 8.1.0, < 9.2.7≥ 9.3.0, < 9.3.42023-11-21
CVE-2023-22516 [HIGH] CVE-2023-22516: This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 8.1.0, 8.2.0 This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 8.1.0, 8.2.0, 9.0.0, 9.1.0, 9.2.0, and 9.3.0 of Bamboo Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.5, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to int
nvd
CVE-2022-26136CRITICALCVSS 9.8≥ 7.2.0, < 7.2.10≥ 8.0.0, < 8.0.9+2 more2022-07-20
CVE-2022-26136 [CRITICAL] CWE-180 CVE-2022-26136: A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass S A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulnerability can result in authentication bypass and cross-site scripting. Atlassian has released update
nvd
CVE-2022-26137HIGHCVSS 8.8≥ 7.2.0, < 7.2.10≥ 8.0.0, < 8.0.9+2 more2022-07-20
CVE-2022-26137 [HIGH] CWE-180 CVE-2022-26137: A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause ad A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security issue associated with this vulnerability: Cross-origin resource sharing (CORS) bypass. Sending a speci
nvd
CVE-2021-26067MEDIUMCVSS 5.3fixed in 7.2.2≥ unspecified, < 7.2.22021-01-28
CVE-2021-26067 [MEDIUM] CWE-200 CVE-2021-26067: Affected versions of Atlassian Bamboo allow an unauthenticated remote attacker to view a stack trace Affected versions of Atlassian Bamboo allow an unauthenticated remote attacker to view a stack trace that may reveal the path for the home directory in disk and if certain files exists on the tmp directory, via a Sensitive Data Exposure vulnerability in the /chart endpoint. The affected versions are before version 7.2.2.
cvelistv5nvd
CVE-2019-15005MEDIUMCVSS 4.3fixed in 6.10.2≥ unspecified, < 6.10.22019-11-08
CVE-2019-15005 [MEDIUM] CWE-862 CVE-2019-15005: The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivilege The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message may contain configuration information about the application that the plugin is installed into. A vulne
cvelistv5nvd
CVE-2018-5224HIGHCVSS 8.8≥ 2.7.0, < 6.3.3≥ 6.4.0, < 6.4.1+4 more2018-03-29
CVE-2018-5224 [HIGH] CWE-20 CVE-2018-5224: Bamboo did not correctly check if a configured Mercurial repository URI contained values that the Wi Bamboo did not correctly check if a configured Mercurial repository URI contained values that the Windows operating system may consider argument parameters. An attacker who has permission to create a repository in Bamboo, edit an existing plan in Bamboo that has a non-linked Mercurial repository, or create a plan in Bamboo either globally or in a project
cvelistv5nvd
CVE-2017-18042HIGHCVSS 8.8fixed in 6.3.1vprior to 6.3.12018-02-02
CVE-2017-18042 [HIGH] CWE-352 CVE-2017-18042: The update user administration resource in Atlassian Bamboo before version 6.3.1 allows remote attac The update user administration resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to modify user data including passwords via a Cross-site request forgery (CSRF) vulnerability.
cvelistv5nvd
CVE-2017-18080HIGHCVSS 8.8fixed in 6.3.1vprior to 6.3.12018-02-02
CVE-2017-18080 [HIGH] CWE-352 CVE-2017-18080: The saveConfigureSecurity resource in Atlassian Bamboo before version 6.3.1 allows remote attackers The saveConfigureSecurity resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to modify security settings via a Cross-site request forgery (CSRF) vulnerability.
cvelistv5nvd
CVE-2017-18082MEDIUMCVSS 5.4fixed in 6.2.3vprior to 6.2.32018-02-02
CVE-2017-18082 [MEDIUM] CWE-79 CVE-2017-18082: The plan configure branches resource in Atlassian Bamboo before version 6.2.3 allows remote attacker The plan configure branches resource in Atlassian Bamboo before version 6.2.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a branch.
cvelistv5nvd
CVE-2017-18040MEDIUMCVSS 5.4fixed in 6.2vprior to 6.2.02018-02-02
CVE-2017-18040 [MEDIUM] CWE-79 CVE-2017-18040: The viewDeploymentVersionCommits resource in Atlassian Bamboo before version 6.2.0 allows remote att The viewDeploymentVersionCommits resource in Atlassian Bamboo before version 6.2.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a release.
cvelistv5nvd
CVE-2017-18081MEDIUMCVSS 6.1fixed in 6.3.1vprior to 6.3.12018-02-02
CVE-2017-18081 [MEDIUM] CWE-79 CVE-2017-18081: The signupUser resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to inject a The signupUser resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the value of the csrf token cookie.
cvelistv5nvd
CVE-2017-18041MEDIUMCVSS 5.4fixed in 6.2.0vprior to 6.2.02018-02-02
CVE-2017-18041 [MEDIUM] CWE-79 CVE-2017-18041: The viewDeploymentVersionJiraIssuesDialog resource in Atlassian Bamboo before version 6.2.0 allows r The viewDeploymentVersionJiraIssuesDialog resource in Atlassian Bamboo before version 6.2.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a release.
cvelistv5nvd
CVE-2017-14590CRITICALCVSS 9.1≥ 2.7.0, < 6.1.6≥ 6.2.0, < 6.2.5+2 more2017-12-13
CVE-2017-14590 [CRITICAL] CVE-2017-14590: Bamboo did not check that the name of a branch in a Mercurial repository contained argument paramete Bamboo did not check that the name of a branch in a Mercurial repository contained argument parameters. An attacker who has permission to create a repository in Bamboo, edit an existing plan that has a non-linked Mercurialrepository, create or edit a plan when there is at least one linked Mercurial repository that the attacker has permission to use, or co
cvelistv5nvd
CVE-2017-14589CRITICALCVSS 9.6fixed in 6.1.6≥ 6.2.0, < 6.2.5+2 more2017-12-13
CVE-2017-14589 [CRITICAL] CWE-20 CVE-2017-14589: It was possible for double OGNL evaluation in FreeMarker templates through Struts FreeMarker tags to It was possible for double OGNL evaluation in FreeMarker templates through Struts FreeMarker tags to occur. An attacker who has restricted administration rights to Bamboo or who hosts a website that a Bamboo administrator visits, is able to exploit this vulnerability to execute Java code of their choice on systems that run a vulnerable version of B
cvelistv5nvd
CVE-2017-9514HIGHCVSS 8.8v6.0.0v6.0.1+9 more2017-10-12
CVE-2017-9514 [HIGH] CWE-732 CVE-2017-9514: Bamboo before 6.0.5, 6.1.x before 6.1.4, and 6.2.x before 6.2.1 had a REST endpoint that parsed a YA Bamboo before 6.0.5, 6.1.x before 6.1.4, and 6.2.x before 6.2.1 had a REST endpoint that parsed a YAML file and did not sufficiently restrict which classes could be loaded. An attacker who can log in to Bamboo as a user is able to exploit this vulnerability to execute Java code of their choice on systems that have vulnerable versions of Bamboo.
cvelistv5nvd
CVE-2015-6576HIGHCVSS 8.8≥ 2.2, < 5.8.5≥ 5.9, < 5.9.72017-10-03
CVE-2015-6576 [HIGH] CWE-94 CVE-2015-6576: Bamboo 2.2 before 5.8.5 and 5.9.x before 5.9.7 allows remote attackers with access to the Bamboo web Bamboo 2.2 before 5.8.5 and 5.9.x before 5.9.7 allows remote attackers with access to the Bamboo web interface to execute arbitrary Java code via an unspecified resource.
nvd
CVE-2017-8907HIGHCVSS 8.8v5.0v5.0.1+47 more2017-06-14
CVE-2017-8907 [HIGH] CWE-863 CVE-2017-8907: Atlassian Bamboo 5.x before 5.15.7 and 6.x before 6.0.1 did not correctly check if a user creating a Atlassian Bamboo 5.x before 5.15.7 and 6.x before 6.0.1 did not correctly check if a user creating a deployment project had the edit permission and therefore the rights to do so. An attacker who can login to Bamboo as a user without the edit permission for deployment projects is able to use this vulnerability, provided there is an existing plan with a g
nvd
CVE-2016-5229CRITICALCVSS 9.8≤ 5.11.3v5.12.0+2 more2016-08-02
CVE-2016-5229 [CRITICAL] CWE-284 CVE-2016-5229: Atlassian Bamboo before 5.11.4.1 and 5.12.x before 5.12.3.1 does not properly restrict permitted des Atlassian Bamboo before 5.11.4.1 and 5.12.x before 5.12.3.1 does not properly restrict permitted deserialized classes, which allows remote attackers to execute arbitrary code via vectors related to XStream Serialization.
nvd