Atlassian

Bamboo

24 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.14%
  • Veröffentlicht 02.02.2018 14:29:01
  • Zuletzt bearbeitet 21.11.2024 03:19:19

The saveConfigureSecurity resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to modify security settings via a Cross-site request forgery (CSRF) vulnerability.

  • EPSS 0.13%
  • Veröffentlicht 02.02.2018 14:29:00
  • Zuletzt bearbeitet 21.11.2024 03:19:14

The update user administration resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to modify user data including passwords via a Cross-site request forgery (CSRF) vulnerability.

  • EPSS 0.14%
  • Veröffentlicht 02.02.2018 14:29:00
  • Zuletzt bearbeitet 21.11.2024 03:19:13

The viewDeploymentVersionJiraIssuesDialog resource in Atlassian Bamboo before version 6.2.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a release.

  • EPSS 0.14%
  • Veröffentlicht 02.02.2018 14:29:00
  • Zuletzt bearbeitet 21.11.2024 03:19:13

The viewDeploymentVersionCommits resource in Atlassian Bamboo before version 6.2.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a release.

  • EPSS 0.49%
  • Veröffentlicht 13.12.2017 15:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Bamboo did not check that the name of a branch in a Mercurial repository contained argument parameters. An attacker who has permission to create a repository in Bamboo, edit an existing plan that has a non-linked Mercurialrepository, create or edit a...

  • EPSS 0.44%
  • Veröffentlicht 13.12.2017 15:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

It was possible for double OGNL evaluation in FreeMarker templates through Struts FreeMarker tags to occur. An attacker who has restricted administration rights to Bamboo or who hosts a website that a Bamboo administrator visits, is able to exploit t...

  • EPSS 0.31%
  • Veröffentlicht 12.10.2017 13:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Bamboo before 6.0.5, 6.1.x before 6.1.4, and 6.2.x before 6.2.1 had a REST endpoint that parsed a YAML file and did not sufficiently restrict which classes could be loaded. An attacker who can log in to Bamboo as a user is able to exploit this vulner...

  • EPSS 2.27%
  • Veröffentlicht 03.10.2017 01:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Bamboo 2.2 before 5.8.5 and 5.9.x before 5.9.7 allows remote attackers with access to the Bamboo web interface to execute arbitrary Java code via an unspecified resource.

  • EPSS 0.85%
  • Veröffentlicht 14.06.2017 20:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Atlassian Bamboo 5.x before 5.15.7 and 6.x before 6.0.1 did not correctly check if a user creating a deployment project had the edit permission and therefore the rights to do so. An attacker who can login to Bamboo as a user without the edit permiss...

  • EPSS 6.03%
  • Veröffentlicht 02.08.2016 16:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Atlassian Bamboo before 5.11.4.1 and 5.12.x before 5.12.3.1 does not properly restrict permitted deserialized classes, which allows remote attackers to execute arbitrary code via vectors related to XStream Serialization.