CVE-2017-18080
- EPSS 0.54%
- Veröffentlicht 02.02.2018 14:29:01
- Zuletzt bearbeitet 21.11.2024 03:19:19
The saveConfigureSecurity resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to modify security settings via a Cross-site request forgery (CSRF) vulnerability.
CVE-2017-18082
- EPSS 0.58%
- Veröffentlicht 02.02.2018 14:29:01
- Zuletzt bearbeitet 21.11.2024 03:19:19
The plan configure branches resource in Atlassian Bamboo before version 6.2.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a branch.
CVE-2017-18081
- EPSS 0.81%
- Veröffentlicht 02.02.2018 14:29:01
- Zuletzt bearbeitet 21.11.2024 03:19:19
The signupUser resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the value of the csrf token cookie.
CVE-2017-18042
- EPSS 0.66%
- Veröffentlicht 02.02.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:14
The update user administration resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to modify user data including passwords via a Cross-site request forgery (CSRF) vulnerability.
CVE-2017-18041
- EPSS 0.61%
- Veröffentlicht 02.02.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:13
The viewDeploymentVersionJiraIssuesDialog resource in Atlassian Bamboo before version 6.2.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a release.
CVE-2017-18040
- EPSS 0.61%
- Veröffentlicht 02.02.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:13
The viewDeploymentVersionCommits resource in Atlassian Bamboo before version 6.2.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a release.
CVE-2017-14590
- EPSS 2.41%
- Veröffentlicht 13.12.2017 15:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Bamboo did not check that the name of a branch in a Mercurial repository contained argument parameters. An attacker who has permission to create a repository in Bamboo, edit an existing plan that has a non-linked Mercurialrepository, create or edit a...
CVE-2017-14589
- EPSS 1.87%
- Veröffentlicht 13.12.2017 15:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
It was possible for double OGNL evaluation in FreeMarker templates through Struts FreeMarker tags to occur. An attacker who has restricted administration rights to Bamboo or who hosts a website that a Bamboo administrator visits, is able to exploit t...
CVE-2017-9514
- EPSS 1.05%
- Veröffentlicht 12.10.2017 13:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Bamboo before 6.0.5, 6.1.x before 6.1.4, and 6.2.x before 6.2.1 had a REST endpoint that parsed a YAML file and did not sufficiently restrict which classes could be loaded. An attacker who can log in to Bamboo as a user is able to exploit this vulner...
CVE-2015-6576
- EPSS 3.67%
- Veröffentlicht 03.10.2017 01:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Bamboo 2.2 before 5.8.5 and 5.9.x before 5.9.7 allows remote attackers with access to the Bamboo web interface to execute arbitrary Java code via an unspecified resource.