cbcvebase.

Atlassian Bamboo vulnerabilities

24 known vulnerabilities affecting atlassian/bamboo.

Total CVEs
24
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH10MEDIUM6

Vulnerabilities

Page 1 of 2
CVE-2012-2926P2CRITICALCVSS 9.1PoCfixed in 3.3.4≥ 3.4, < 3.4.52012-05-22
CVE-2012-2926 [CRITICAL] CVE-2012-2926: Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; Fish Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 before 2.6.8, and 2.7 before 2.7.12; Bamboo before 3.3.4 and 3.4.x before 3.4.5; and Crowd before 2.0.9, 2.1 before 2.1.2, 2.2 before 2.2.9, 2.3 before 2.3.7, and 2.4 before 2.4.1 do not properly restrict the capabilities of
nvd
CVE-2022-26136P2CRITICALCVSS 9.8≥ 7.2.0, < 7.2.10≥ 8.0.0, < 8.0.9+2 more2022-07-20
CVE-2022-26136 [CRITICAL] CWE-180 CVE-2022-26136: A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass S A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulnerability can result in authentication bypass and cross-site scripting. Atlassian has released update
nvd
CVE-2016-5229P2CRITICALCVSS 9.8≤ 5.11.3v5.12.0+2 more2016-08-02
CVE-2016-5229 [CRITICAL] CWE-284 CVE-2016-5229: Atlassian Bamboo before 5.11.4.1 and 5.12.x before 5.12.3.1 does not properly restrict permitted des Atlassian Bamboo before 5.11.4.1 and 5.12.x before 5.12.3.1 does not properly restrict permitted deserialized classes, which allows remote attackers to execute arbitrary code via vectors related to XStream Serialization.
nvd
CVE-2015-8360P3CRITICALCVSS 9.8v2.3.1v2.4+85 more2016-02-08
CVE-2015-8360 [CRITICAL] CWE-20 CVE-2015-8360: An unspecified resource in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 allows remote atta An unspecified resource in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 allows remote attackers to execute arbitrary Java code via serialized data to the JMS port.
nvd
CVE-2023-22516P2HIGHCVSS 8.8≥ 8.1.0, < 9.2.7≥ 9.3.0, < 9.3.42023-11-21
CVE-2023-22516 [HIGH] CVE-2023-22516: This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 8.1.0, 8.2.0 This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 8.1.0, 8.2.0, 9.0.0, 9.1.0, 9.2.0, and 9.3.0 of Bamboo Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.5, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to int
nvd
CVE-2014-9757P3CRITICALCVSS 9.8v2.4v2.4.1+84 more2016-02-08
CVE-2014-9757 [CRITICAL] CWE-20 CVE-2014-9757: The Ignite Realtime Smack XMPP API, as used in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10. The Ignite Realtime Smack XMPP API, as used in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0, allows remote configured XMPP servers to execute arbitrary Java code via serialized data in an XMPP message.
nvd
CVE-2015-6576P3HIGHCVSS 8.8≥ 2.2, < 5.8.5≥ 5.9, < 5.9.72017-10-03
CVE-2015-6576 [HIGH] CWE-94 CVE-2015-6576: Bamboo 2.2 before 5.8.5 and 5.9.x before 5.9.7 allows remote attackers with access to the Bamboo web Bamboo 2.2 before 5.8.5 and 5.9.x before 5.9.7 allows remote attackers with access to the Bamboo web interface to execute arbitrary Java code via an unspecified resource.
nvd
CVE-2022-26137P3HIGHCVSS 8.8≥ 7.2.0, < 7.2.10≥ 8.0.0, < 8.0.9+2 more2022-07-20
CVE-2022-26137 [HIGH] CWE-180 CVE-2022-26137: A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause ad A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security issue associated with this vulnerability: Cross-origin resource sharing (CORS) bypass. Sending a speci
nvd
CVE-2015-8361P3CRITICALCVSS 9.1v2.4v2.4.1+84 more2016-02-08
CVE-2015-8361 [CRITICAL] CWE-284 CVE-2015-8361: Multiple unspecified services in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 do not requi Multiple unspecified services in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 do not require authentication, which allows remote attackers to obtain sensitive information, modify settings, or manage build agents via unknown vectors involving the JMS port.
nvd
CVE-2018-5224P3HIGHCVSS 8.8≥ 2.7.0, < 6.3.3≥ 6.4.0, < 6.4.1+4 more2018-03-29
CVE-2018-5224 [HIGH] CWE-20 CVE-2018-5224: Bamboo did not correctly check if a configured Mercurial repository URI contained values that the Wi Bamboo did not correctly check if a configured Mercurial repository URI contained values that the Windows operating system may consider argument parameters. An attacker who has permission to create a repository in Bamboo, edit an existing plan in Bamboo that has a non-linked Mercurial repository, or create a plan in Bamboo either globally or in a project
nvd
CVE-2024-21689P3HIGHCVSS 8.0≥ 9.1.0, < 9.2.17≥ 9.3.0, < 9.6.52024-08-20
CVE-2024-21689 [HIGH] CWE-94 CVE-2024-21689: This High severity RCE (Remote Code Execution) vulnerability CVE-2024-21689 was introduced in versi This High severity RCE (Remote Code Execution) vulnerability CVE-2024-21689 was introduced in versions 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0, and 9.6.0 of Bamboo Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.6, allows an authenticated attacker to execute arbitrary code which has high impact to confidentialit
nvd
CVE-2017-8907P3HIGHCVSS 8.8v5.0v5.0.1+47 more2017-06-14
CVE-2017-8907 [HIGH] CWE-863 CVE-2017-8907: Atlassian Bamboo 5.x before 5.15.7 and 6.x before 6.0.1 did not correctly check if a user creating a Atlassian Bamboo 5.x before 5.15.7 and 6.x before 6.0.1 did not correctly check if a user creating a deployment project had the edit permission and therefore the rights to do so. An attacker who can login to Bamboo as a user without the edit permission for deployment projects is able to use this vulnerability, provided there is an existing plan with a g
nvd
CVE-2017-14589P3CRITICALCVSS 9.6fixed in 6.1.6≥ 6.2.0, < 6.2.5+2 more2017-12-13
CVE-2017-14589 [CRITICAL] CWE-20 CVE-2017-14589: It was possible for double OGNL evaluation in FreeMarker templates through Struts FreeMarker tags to It was possible for double OGNL evaluation in FreeMarker templates through Struts FreeMarker tags to occur. An attacker who has restricted administration rights to Bamboo or who hosts a website that a Bamboo administrator visits, is able to exploit this vulnerability to execute Java code of their choice on systems that run a vulnerable version of B
nvd
CVE-2017-14590P3CRITICALCVSS 9.1≥ 2.7.0, < 6.1.6≥ 6.2.0, < 6.2.5+2 more2017-12-13
CVE-2017-14590 [CRITICAL] CVE-2017-14590: Bamboo did not check that the name of a branch in a Mercurial repository contained argument paramete Bamboo did not check that the name of a branch in a Mercurial repository contained argument parameters. An attacker who has permission to create a repository in Bamboo, edit an existing plan that has a non-linked Mercurialrepository, create or edit a plan when there is at least one linked Mercurial repository that the attacker has permission to use, or co
nvd
CVE-2024-21687P3HIGHCVSS 8.1≥ 9.0.0, ≤ 9.0.4≥ 9.1.0, ≤ 9.1.3+5 more2024-07-16
CVE-2024-21687 [HIGH] CWE-98 CVE-2024-21687: This High severity File Inclusion vulnerability was introduced in versions 9.0.0, 9.1.0, 9.2.0, 9.3. This High severity File Inclusion vulnerability was introduced in versions 9.0.0, 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0 and 9.6.0 of Bamboo Data Center and Server. This File Inclusion vulnerability, with a CVSS Score of 8.1, allows an authenticated attacker to get the application to display the contents of a local file, or execute a different files alread
nvd
CVE-2017-9514P3HIGHCVSS 8.8v6.0.0v6.0.1+9 more2017-10-12
CVE-2017-9514 [HIGH] CWE-732 CVE-2017-9514: Bamboo before 6.0.5, 6.1.x before 6.1.4, and 6.2.x before 6.2.1 had a REST endpoint that parsed a YA Bamboo before 6.0.5, 6.1.x before 6.1.4, and 6.2.x before 6.2.1 had a REST endpoint that parsed a YAML file and did not sufficiently restrict which classes could be loaded. An attacker who can log in to Bamboo as a user is able to exploit this vulnerability to execute Java code of their choice on systems that have vulnerable versions of Bamboo.
nvd
CVE-2017-18042P3HIGHCVSS 8.8fixed in 6.3.1vprior to 6.3.12018-02-02
CVE-2017-18042 [HIGH] CWE-352 CVE-2017-18042: The update user administration resource in Atlassian Bamboo before version 6.3.1 allows remote attac The update user administration resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to modify user data including passwords via a Cross-site request forgery (CSRF) vulnerability.
nvd
CVE-2017-18080P4HIGHCVSS 8.8fixed in 6.3.1vprior to 6.3.12018-02-02
CVE-2017-18080 [HIGH] CWE-352 CVE-2017-18080: The saveConfigureSecurity resource in Atlassian Bamboo before version 6.3.1 allows remote attackers The saveConfigureSecurity resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to modify security settings via a Cross-site request forgery (CSRF) vulnerability.
nvd
CVE-2021-26067P4MEDIUMCVSS 5.3fixed in 7.2.2≥ unspecified, < 7.2.22021-01-28
CVE-2021-26067 [MEDIUM] CWE-200 CVE-2021-26067: Affected versions of Atlassian Bamboo allow an unauthenticated remote attacker to view a stack trace Affected versions of Atlassian Bamboo allow an unauthenticated remote attacker to view a stack trace that may reveal the path for the home directory in disk and if certain files exists on the tmp directory, via a Sensitive Data Exposure vulnerability in the /chart endpoint. The affected versions are before version 7.2.2.
nvd
CVE-2019-15005P4MEDIUMCVSS 4.3fixed in 6.10.2≥ unspecified, < 6.10.22019-11-08
CVE-2019-15005 [MEDIUM] CWE-862 CVE-2019-15005: The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivilege The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message may contain configuration information about the application that the plugin is installed into. A vulne
nvd
Atlassian Bamboo vulnerabilities | cvebase