Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
atlassian bamboo 5.9 vulnerabilities and exploits
(subscribe to this query)
8.8
CVSSv3
CVE-2015-6576
Bamboo 2.2 prior to 5.8.5 and 5.9.x prior to 5.9.7 allows remote attackers with access to the Bamboo web interface to execute arbitrary Java code via an unspecified resource.
Atlassian Bamboo
3 Github repositories
8.8
CVSSv3
CVE-2017-8907
Atlassian Bamboo 5.x prior to 5.15.7 and 6.x prior to 6.0.1 did not correctly check if a user creating a deployment project had the edit permission and therefore the rights to do so. An attacker who can login to Bamboo as a user without the edit permission for deployment projects...
Atlassian Bamboo 6.0.0
Atlassian Bamboo 5.15.5
Atlassian Bamboo 5.15.3
Atlassian Bamboo 5.15.4
Atlassian Bamboo 5.3
Atlassian Bamboo 5.4
Atlassian Bamboo 5.4.1
Atlassian Bamboo 5.4.2
Atlassian Bamboo 5.9.2
Atlassian Bamboo 5.9.3
Atlassian Bamboo 5.9.4
Atlassian Bamboo 5.9.7
Atlassian Bamboo 5.14.2
Atlassian Bamboo 5.14.1
Atlassian Bamboo 5.13.0
Atlassian Bamboo 5.12.5
Atlassian Bamboo 5.15.0
Atlassian Bamboo 5.0
Atlassian Bamboo 5.2
Atlassian Bamboo 5.2.2
Atlassian Bamboo 5.5
Atlassian Bamboo 5.6.1
9.8
CVSSv3
CVE-2015-8360
An unspecified resource in Atlassian Bamboo prior to 5.9.9 and 5.10.x prior to 5.10.0 allows remote malicious users to execute arbitrary Java code via serialized data to the JMS port.
Atlassian Bamboo 3.2
Atlassian Bamboo 5.9.7
Atlassian Bamboo 5.9.4
Atlassian Bamboo 5.8.1
Atlassian Bamboo 5.8
Atlassian Bamboo 5.5
Atlassian Bamboo 5.4.2
Atlassian Bamboo 5.1
Atlassian Bamboo 5.0.1
Atlassian Bamboo 4.4.5
Atlassian Bamboo 4.4.4
Atlassian Bamboo 4.3.2
Atlassian Bamboo 4.3.1
Atlassian Bamboo 4.0
Atlassian Bamboo 3.4.5
Atlassian Bamboo 3.3.3
Atlassian Bamboo 3.3.2
Atlassian Bamboo 3.1
Atlassian Bamboo 3.0.3
Atlassian Bamboo 2.7
Atlassian Bamboo 2.6.3
Atlassian Bamboo 2.5.1
9.1
CVSSv3
CVE-2015-8361
Multiple unspecified services in Atlassian Bamboo prior to 5.9.9 and 5.10.x prior to 5.10.0 do not require authentication, which allows remote malicious users to obtain sensitive information, modify settings, or manage build agents via unknown vectors involving the JMS port.
Atlassian Bamboo 5.9.4
Atlassian Bamboo 5.9.3
Atlassian Bamboo 5.7.2
Atlassian Bamboo 5.7.1
Atlassian Bamboo 5.4.1
Atlassian Bamboo 5.4
Atlassian Bamboo 5.9.2
Atlassian Bamboo 5.9.1
Atlassian Bamboo 5.9
Atlassian Bamboo 5.7
Atlassian Bamboo 5.6.2
Atlassian Bamboo 5.3
Atlassian Bamboo 5.2.2
Atlassian Bamboo 5.0
Atlassian Bamboo 4.4.1
Atlassian Bamboo 4.4
Atlassian Bamboo 4.2
Atlassian Bamboo 4.1.2
Atlassian Bamboo 3.4.3
Atlassian Bamboo 3.4.2
Atlassian Bamboo 3.2.2
Atlassian Bamboo 3.2
9.8
CVSSv3
CVE-2014-9757
The Ignite Realtime Smack XMPP API, as used in Atlassian Bamboo prior to 5.9.9 and 5.10.x prior to 5.10.0, allows remote configured XMPP servers to execute arbitrary Java code via serialized data in an XMPP message.
Atlassian Bamboo 5.9.7
Atlassian Bamboo 5.9.4
Atlassian Bamboo 5.8
Atlassian Bamboo 5.7.2
Atlassian Bamboo 5.4.2
Atlassian Bamboo 5.4.1
Atlassian Bamboo 5.1
Atlassian Bamboo 5.0.1
Atlassian Bamboo 5.0
Atlassian Bamboo 4.4.5
Atlassian Bamboo 4.4.4
Atlassian Bamboo 4.3.2
Atlassian Bamboo 4.3.1
Atlassian Bamboo 4.0
Atlassian Bamboo 3.4.5
Atlassian Bamboo 3.3.3
Atlassian Bamboo 3.3.2
Atlassian Bamboo 3.3
Atlassian Bamboo 3.0.3
Atlassian Bamboo 2.7
Atlassian Bamboo 2.6.3
Atlassian Bamboo 2.5.1
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4644
unprivileged
CVE-2024-3494
CVE-2024-22460
CVE-2024-26026
CVE-2024-23473
firewall
CVE-2024-28889
XML external entity
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started