- EPSS 31.98%
- Veröffentlicht 20.08.2024 10:15:04
- Zuletzt bearbeitet 13.03.2025 16:15:17
This High severity RCE (Remote Code Execution) vulnerability CVE-2024-21689 was introduced in versions 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0, and 9.6.0 of Bamboo Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Scor...
CVE-2024-21687
- EPSS 1.06%
- Veröffentlicht 16.07.2024 21:15:10
- Zuletzt bearbeitet 14.03.2025 16:15:28
This High severity File Inclusion vulnerability was introduced in versions 9.0.0, 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0 and 9.6.0 of Bamboo Data Center and Server. This File Inclusion vulnerability, with a CVSS Score of 8.1, allows an authenticated atta...
CVE-2023-22516
- EPSS 1.73%
- Veröffentlicht 21.11.2023 18:15:07
- Zuletzt bearbeitet 21.11.2024 07:44:58
This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 8.1.0, 8.2.0, 9.0.0, 9.1.0, 9.2.0, and 9.3.0 of Bamboo Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.5, allows...
CVE-2022-26137
- EPSS 0.07%
- Veröffentlicht 20.07.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:53:30
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security...
CVE-2022-26136
- EPSS 0.28%
- Veröffentlicht 20.07.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:53:30
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulner...
CVE-2021-26067
- EPSS 1.53%
- Veröffentlicht 28.01.2021 02:15:12
- Zuletzt bearbeitet 21.11.2024 05:55:48
Affected versions of Atlassian Bamboo allow an unauthenticated remote attacker to view a stack trace that may reveal the path for the home directory in disk and if certain files exists on the tmp directory, via a Sensitive Data Exposure vulnerability...
CVE-2019-15005
- EPSS 0.21%
- Veröffentlicht 08.11.2019 04:15:10
- Zuletzt bearbeitet 21.11.2024 04:27:51
The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message m...
- EPSS 0.93%
- Veröffentlicht 29.03.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 04:08:22
Bamboo did not correctly check if a configured Mercurial repository URI contained values that the Windows operating system may consider argument parameters. An attacker who has permission to create a repository in Bamboo, edit an existing plan in Bam...
CVE-2017-18082
- EPSS 0.16%
- Veröffentlicht 02.02.2018 14:29:01
- Zuletzt bearbeitet 21.11.2024 03:19:19
The plan configure branches resource in Atlassian Bamboo before version 6.2.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a branch.
CVE-2017-18081
- EPSS 0.19%
- Veröffentlicht 02.02.2018 14:29:01
- Zuletzt bearbeitet 21.11.2024 03:19:19
The signupUser resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the value of the csrf token cookie.