Atlassian Bamboo vulnerabilities
24 known vulnerabilities affecting atlassian/bamboo.
Total CVEs
24
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH10MEDIUM6
Vulnerabilities
Page 2 of 2
CVE-2017-18081P4MEDIUMCVSS 6.1fixed in 6.3.1vprior to 6.3.12018-02-02
CVE-2017-18081 [MEDIUM] CWE-79 CVE-2017-18081: The signupUser resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to inject a
The signupUser resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the value of the csrf token cookie.
nvd
CVE-2017-18041P4MEDIUMCVSS 5.4fixed in 6.2.0vprior to 6.2.02018-02-02
CVE-2017-18041 [MEDIUM] CWE-79 CVE-2017-18041: The viewDeploymentVersionJiraIssuesDialog resource in Atlassian Bamboo before version 6.2.0 allows r
The viewDeploymentVersionJiraIssuesDialog resource in Atlassian Bamboo before version 6.2.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a release.
nvd
CVE-2017-18040P4MEDIUMCVSS 5.4fixed in 6.2vprior to 6.2.02018-02-02
CVE-2017-18040 [MEDIUM] CWE-79 CVE-2017-18040: The viewDeploymentVersionCommits resource in Atlassian Bamboo before version 6.2.0 allows remote att
The viewDeploymentVersionCommits resource in Atlassian Bamboo before version 6.2.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a release.
nvd
CVE-2017-18082P4MEDIUMCVSS 5.4fixed in 6.2.3vprior to 6.2.32018-02-02
CVE-2017-18082 [MEDIUM] CWE-79 CVE-2017-18082: The plan configure branches resource in Atlassian Bamboo before version 6.2.3 allows remote attacker
The plan configure branches resource in Atlassian Bamboo before version 6.2.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a branch.
nvd
← Previous2 / 2