Atlassian Bamboo vulnerabilities
27 known vulnerabilities affecting atlassian/bamboo.
Total CVEs
27
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH13MEDIUM6
Vulnerabilities
Page 1 of 2
CVE-2012-2926P2CRITICALCVSS 9.1PoCfixed in 3.3.4≥ 3.4, < 3.4.52012-05-22
CVE-2012-2926 [CRITICAL] CVE-2012-2926: Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; Fish
Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 before 2.6.8, and 2.7 before 2.7.12; Bamboo before 3.3.4 and 3.4.x before 3.4.5; and Crowd before 2.0.9, 2.1 before 2.1.2, 2.2 before 2.2.9, 2.3 before 2.3.7, and 2.4 before 2.4.1 do not properly restrict the capabilities of
nvd
CVE-2022-26136P2CRITICALCVSS 9.8≥ 7.2.0, < 7.2.10≥ 8.0.0, < 8.0.9+2 more2022-07-20
CVE-2022-26136 [CRITICAL] CWE-180 CVE-2022-26136: A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass S
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulnerability can result in authentication bypass and cross-site scripting. Atlassian has released update
nvd
CVE-2016-5229P2CRITICALCVSS 9.8≤ 5.11.3v5.12.0+2 more2016-08-02
CVE-2016-5229 [CRITICAL] CWE-284 CVE-2016-5229: Atlassian Bamboo before 5.11.4.1 and 5.12.x before 5.12.3.1 does not properly restrict permitted des
Atlassian Bamboo before 5.11.4.1 and 5.12.x before 5.12.3.1 does not properly restrict permitted deserialized classes, which allows remote attackers to execute arbitrary code via vectors related to XStream Serialization.
nvd
CVE-2026-21571P2HIGHCVSS 8.8≥ 9.6.2, < 9.6.25≥ 10.0.0, < 10.2.18+1 more2026-04-21
CVE-2026-21571 [HIGH] CWE-78 CVE-2026-21571: This Critical severity OS Command Injection vulnerability was introduced in versions 9.6.0, 10.0.0,
This Critical severity OS Command Injection vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0,
11.0.0, 11.1.0, 12.0.0, and 12.1.0 of Bamboo Data Center.
This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 9.4 and a CVSS Vector of
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H allows an authenticate
nvd
CVE-2026-21570P2HIGHCVSS 8.8≥ 9.6.1, < 9.6.24≥ 10.0.0, < 10.2.16+1 more2026-03-17
CVE-2026-21570 [HIGH] CWE-94 CVE-2026-21570: This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 9.6.0, 10.0
This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 12.1.0 of Bamboo Data Center.
This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.6, allows an authenticated attacker to execute malicious code on the remote system.
Atlassian recommends
nvd
CVE-2015-8360P3CRITICALCVSS 9.8v2.3.1v2.4+85 more2016-02-08
CVE-2015-8360 [CRITICAL] CWE-20 CVE-2015-8360: An unspecified resource in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 allows remote atta
An unspecified resource in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 allows remote attackers to execute arbitrary Java code via serialized data to the JMS port.
nvd
CVE-2023-22516P2HIGHCVSS 8.8≥ 8.1.0, < 9.2.7≥ 9.3.0, < 9.3.42023-11-21
CVE-2023-22516 [HIGH] CVE-2023-22516: This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 8.1.0, 8.2.0
This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 8.1.0, 8.2.0, 9.0.0, 9.1.0, 9.2.0, and 9.3.0 of Bamboo Data Center and Server.
This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.5, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to int
nvd
CVE-2014-9757P3CRITICALCVSS 9.8v2.4v2.4.1+84 more2016-02-08
CVE-2014-9757 [CRITICAL] CWE-20 CVE-2014-9757: The Ignite Realtime Smack XMPP API, as used in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.
The Ignite Realtime Smack XMPP API, as used in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0, allows remote configured XMPP servers to execute arbitrary Java code via serialized data in an XMPP message.
nvd
CVE-2015-6576P3HIGHCVSS 8.8≥ 2.2, < 5.8.5≥ 5.9, < 5.9.72017-10-03
CVE-2015-6576 [HIGH] CWE-94 CVE-2015-6576: Bamboo 2.2 before 5.8.5 and 5.9.x before 5.9.7 allows remote attackers with access to the Bamboo web
Bamboo 2.2 before 5.8.5 and 5.9.x before 5.9.7 allows remote attackers with access to the Bamboo web interface to execute arbitrary Java code via an unspecified resource.
nvd
CVE-2026-21584P3HIGHCVSS 8.1≥ 10.0.0, < 10.2.22≥ 11.0.0, < 12.1.102026-08-18
CVE-2026-21584 [HIGH] CWE-285 CVE-2026-21584: This High severity Improper Authorization vulnerability was introduced in versions 10.0.0, 10.1.0, 1
This High severity Improper Authorization vulnerability was introduced in versions 10.0.0, 10.1.0, 10.2.0, 11.0.0, 12.0.0, and 12.1.0 of Bamboo Data Center.
This Improper Authorization vulnerability, with a CVSS Score of 7.6, allows an authenticated attacker to gain unintended access and can lead to the exposure of resources or functionality, possibl
nvd
CVE-2022-26137P3HIGHCVSS 8.8≥ 7.2.0, < 7.2.10≥ 8.0.0, < 8.0.9+2 more2022-07-20
CVE-2022-26137 [HIGH] CWE-180 CVE-2022-26137: A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause ad
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security issue associated with this vulnerability: Cross-origin resource sharing (CORS) bypass. Sending a speci
nvd
CVE-2015-8361P3CRITICALCVSS 9.1v2.4v2.4.1+84 more2016-02-08
CVE-2015-8361 [CRITICAL] CWE-284 CVE-2015-8361: Multiple unspecified services in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 do not requi
Multiple unspecified services in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 do not require authentication, which allows remote attackers to obtain sensitive information, modify settings, or manage build agents via unknown vectors involving the JMS port.
nvd
CVE-2018-5224P3HIGHCVSS 8.8≥ 2.7.0, < 6.3.3≥ 6.4.0, < 6.4.1+4 more2018-03-29
CVE-2018-5224 [HIGH] CWE-20 CVE-2018-5224: Bamboo did not correctly check if a configured Mercurial repository URI contained values that the Wi
Bamboo did not correctly check if a configured Mercurial repository URI contained values that the Windows operating system may consider argument parameters. An attacker who has permission to create a repository in Bamboo, edit an existing plan in Bamboo that has a non-linked Mercurial repository, or create a plan in Bamboo either globally or in a project
nvd
CVE-2017-8907P3HIGHCVSS 8.8v5.0v5.0.1+47 more2017-06-14
CVE-2017-8907 [HIGH] CWE-863 CVE-2017-8907: Atlassian Bamboo 5.x before 5.15.7 and 6.x before 6.0.1 did not correctly check if a user creating a
Atlassian Bamboo 5.x before 5.15.7 and 6.x before 6.0.1 did not correctly check if a user creating a deployment project had the edit permission and therefore the rights to do so. An attacker who can login to Bamboo as a user without the edit permission for deployment projects is able to use this vulnerability, provided there is an existing plan with a g
nvd
CVE-2024-21689P3HIGHCVSS 8.0≥ 9.1.0, < 9.2.17≥ 9.3.0, < 9.6.52024-08-20
CVE-2024-21689 [HIGH] CWE-94 CVE-2024-21689: This High severity RCE (Remote Code Execution) vulnerability CVE-2024-21689 was introduced in versi
This High severity RCE (Remote Code Execution) vulnerability CVE-2024-21689 was introduced in versions 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0, and 9.6.0 of Bamboo Data Center and Server.
This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.6, allows an authenticated attacker to execute arbitrary code which has high impact to confidentialit
nvd
CVE-2017-14589P3CRITICALCVSS 9.6fixed in 6.1.6≥ 6.2.0, < 6.2.5+2 more2017-12-13
CVE-2017-14589 [CRITICAL] CWE-20 CVE-2017-14589: It was possible for double OGNL evaluation in FreeMarker templates through Struts FreeMarker tags to
It was possible for double OGNL evaluation in FreeMarker templates through Struts FreeMarker tags to occur. An attacker who has restricted administration rights to Bamboo or who hosts a website that a Bamboo administrator visits, is able to exploit this vulnerability to execute Java code of their choice on systems that run a vulnerable version of B
nvd
CVE-2017-14590P3CRITICALCVSS 9.1≥ 2.7.0, < 6.1.6≥ 6.2.0, < 6.2.5+2 more2017-12-13
CVE-2017-14590 [CRITICAL] CVE-2017-14590: Bamboo did not check that the name of a branch in a Mercurial repository contained argument paramete
Bamboo did not check that the name of a branch in a Mercurial repository contained argument parameters. An attacker who has permission to create a repository in Bamboo, edit an existing plan that has a non-linked Mercurialrepository, create or edit a plan when there is at least one linked Mercurial repository that the attacker has permission to use, or co
nvd
CVE-2024-21687P3HIGHCVSS 8.1≥ 9.0.0, ≤ 9.0.4≥ 9.1.0, ≤ 9.1.3+5 more2024-07-16
CVE-2024-21687 [HIGH] CWE-98 CVE-2024-21687: This High severity File Inclusion vulnerability was introduced in versions 9.0.0, 9.1.0, 9.2.0, 9.3.
This High severity File Inclusion vulnerability was introduced in versions 9.0.0, 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0 and 9.6.0 of Bamboo Data Center and Server.
This File Inclusion vulnerability, with a CVSS Score of 8.1, allows an authenticated attacker to get the application to display the contents of a local file, or execute a different files alread
nvd
CVE-2017-9514P3HIGHCVSS 8.8v6.0.0v6.0.1+9 more2017-10-12
CVE-2017-9514 [HIGH] CWE-732 CVE-2017-9514: Bamboo before 6.0.5, 6.1.x before 6.1.4, and 6.2.x before 6.2.1 had a REST endpoint that parsed a YA
Bamboo before 6.0.5, 6.1.x before 6.1.4, and 6.2.x before 6.2.1 had a REST endpoint that parsed a YAML file and did not sufficiently restrict which classes could be loaded. An attacker who can log in to Bamboo as a user is able to exploit this vulnerability to execute Java code of their choice on systems that have vulnerable versions of Bamboo.
nvd
CVE-2017-18042P3HIGHCVSS 8.8fixed in 6.3.1vprior to 6.3.12018-02-02
CVE-2017-18042 [HIGH] CWE-352 CVE-2017-18042: The update user administration resource in Atlassian Bamboo before version 6.3.1 allows remote attac
The update user administration resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to modify user data including passwords via a Cross-site request forgery (CSRF) vulnerability.
nvd
1 / 2Next →