CVE-2017-18080
- EPSS 0.14%
- Veröffentlicht 02.02.2018 14:29:01
- Zuletzt bearbeitet 21.11.2024 03:19:19
The saveConfigureSecurity resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to modify security settings via a Cross-site request forgery (CSRF) vulnerability.
CVE-2017-18042
- EPSS 0.13%
- Veröffentlicht 02.02.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:14
The update user administration resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to modify user data including passwords via a Cross-site request forgery (CSRF) vulnerability.
CVE-2017-18041
- EPSS 0.14%
- Veröffentlicht 02.02.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:13
The viewDeploymentVersionJiraIssuesDialog resource in Atlassian Bamboo before version 6.2.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a release.
CVE-2017-18040
- EPSS 0.14%
- Veröffentlicht 02.02.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:13
The viewDeploymentVersionCommits resource in Atlassian Bamboo before version 6.2.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a release.
CVE-2017-14590
- EPSS 0.49%
- Veröffentlicht 13.12.2017 15:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Bamboo did not check that the name of a branch in a Mercurial repository contained argument parameters. An attacker who has permission to create a repository in Bamboo, edit an existing plan that has a non-linked Mercurialrepository, create or edit a...
CVE-2017-14589
- EPSS 0.44%
- Veröffentlicht 13.12.2017 15:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
It was possible for double OGNL evaluation in FreeMarker templates through Struts FreeMarker tags to occur. An attacker who has restricted administration rights to Bamboo or who hosts a website that a Bamboo administrator visits, is able to exploit t...
CVE-2017-9514
- EPSS 0.31%
- Veröffentlicht 12.10.2017 13:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Bamboo before 6.0.5, 6.1.x before 6.1.4, and 6.2.x before 6.2.1 had a REST endpoint that parsed a YAML file and did not sufficiently restrict which classes could be loaded. An attacker who can log in to Bamboo as a user is able to exploit this vulner...
CVE-2015-6576
- EPSS 2.27%
- Veröffentlicht 03.10.2017 01:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Bamboo 2.2 before 5.8.5 and 5.9.x before 5.9.7 allows remote attackers with access to the Bamboo web interface to execute arbitrary Java code via an unspecified resource.
CVE-2017-8907
- EPSS 0.85%
- Veröffentlicht 14.06.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Atlassian Bamboo 5.x before 5.15.7 and 6.x before 6.0.1 did not correctly check if a user creating a deployment project had the edit permission and therefore the rights to do so. An attacker who can login to Bamboo as a user without the edit permiss...
CVE-2016-5229
- EPSS 6.03%
- Veröffentlicht 02.08.2016 16:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
Atlassian Bamboo before 5.11.4.1 and 5.12.x before 5.12.3.1 does not properly restrict permitted deserialized classes, which allows remote attackers to execute arbitrary code via vectors related to XStream Serialization.