Atlassian

Bamboo

24 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.55%
  • Veröffentlicht 02.02.2018 14:29:01
  • Zuletzt bearbeitet 21.11.2024 03:19:19

The saveConfigureSecurity resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to modify security settings via a Cross-site request forgery (CSRF) vulnerability.

  • EPSS 0.67%
  • Veröffentlicht 02.02.2018 14:29:00
  • Zuletzt bearbeitet 21.11.2024 03:19:14

The update user administration resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to modify user data including passwords via a Cross-site request forgery (CSRF) vulnerability.

  • EPSS 0.62%
  • Veröffentlicht 02.02.2018 14:29:00
  • Zuletzt bearbeitet 21.11.2024 03:19:13

The viewDeploymentVersionJiraIssuesDialog resource in Atlassian Bamboo before version 6.2.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a release.

  • EPSS 0.62%
  • Veröffentlicht 02.02.2018 14:29:00
  • Zuletzt bearbeitet 21.11.2024 03:19:13

The viewDeploymentVersionCommits resource in Atlassian Bamboo before version 6.2.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a release.

  • EPSS 2.41%
  • Veröffentlicht 13.12.2017 15:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Bamboo did not check that the name of a branch in a Mercurial repository contained argument parameters. An attacker who has permission to create a repository in Bamboo, edit an existing plan that has a non-linked Mercurialrepository, create or edit a...

  • EPSS 1.87%
  • Veröffentlicht 13.12.2017 15:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

It was possible for double OGNL evaluation in FreeMarker templates through Struts FreeMarker tags to occur. An attacker who has restricted administration rights to Bamboo or who hosts a website that a Bamboo administrator visits, is able to exploit t...

  • EPSS 1.05%
  • Veröffentlicht 12.10.2017 13:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Bamboo before 6.0.5, 6.1.x before 6.1.4, and 6.2.x before 6.2.1 had a REST endpoint that parsed a YAML file and did not sufficiently restrict which classes could be loaded. An attacker who can log in to Bamboo as a user is able to exploit this vulner...

  • EPSS 3.62%
  • Veröffentlicht 03.10.2017 01:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Bamboo 2.2 before 5.8.5 and 5.9.x before 5.9.7 allows remote attackers with access to the Bamboo web interface to execute arbitrary Java code via an unspecified resource.

  • EPSS 1.64%
  • Veröffentlicht 14.06.2017 20:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Atlassian Bamboo 5.x before 5.15.7 and 6.x before 6.0.1 did not correctly check if a user creating a deployment project had the edit permission and therefore the rights to do so. An attacker who can login to Bamboo as a user without the edit permiss...

  • EPSS 7.09%
  • Veröffentlicht 02.08.2016 16:59:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Atlassian Bamboo before 5.11.4.1 and 5.12.x before 5.12.3.1 does not properly restrict permitted deserialized classes, which allows remote attackers to execute arbitrary code via vectors related to XStream Serialization.