Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
atlassian bamboo 5.9.7 vulnerabilities and exploits
(subscribe to this query)
8.8
CVSSv3
CVE-2015-6576
Bamboo 2.2 prior to 5.8.5 and 5.9.x prior to 5.9.7 allows remote attackers with access to the Bamboo web interface to execute arbitrary Java code via an unspecified resource.
Atlassian Bamboo
3 Github repositories
8.8
CVSSv3
CVE-2017-8907
Atlassian Bamboo 5.x prior to 5.15.7 and 6.x prior to 6.0.1 did not correctly check if a user creating a deployment project had the edit permission and therefore the rights to do so. An attacker who can login to Bamboo as a user without the edit permission for deployment projects...
Atlassian Bamboo 6.0.0
Atlassian Bamboo 5.15.5
Atlassian Bamboo 5.15.3
Atlassian Bamboo 5.15.4
Atlassian Bamboo 5.3
Atlassian Bamboo 5.4
Atlassian Bamboo 5.4.1
Atlassian Bamboo 5.4.2
Atlassian Bamboo 5.9.2
Atlassian Bamboo 5.9.3
Atlassian Bamboo 5.9.4
Atlassian Bamboo 5.9.7
Atlassian Bamboo 5.14.2
Atlassian Bamboo 5.14.1
Atlassian Bamboo 5.13.0
Atlassian Bamboo 5.12.5
Atlassian Bamboo 5.15.0
Atlassian Bamboo 5.0
Atlassian Bamboo 5.2
Atlassian Bamboo 5.2.2
Atlassian Bamboo 5.5
Atlassian Bamboo 5.6.1
9.8
CVSSv3
CVE-2014-9757
The Ignite Realtime Smack XMPP API, as used in Atlassian Bamboo prior to 5.9.9 and 5.10.x prior to 5.10.0, allows remote configured XMPP servers to execute arbitrary Java code via serialized data in an XMPP message.
Atlassian Bamboo 5.9.7
Atlassian Bamboo 5.9.4
Atlassian Bamboo 5.8
Atlassian Bamboo 5.7.2
Atlassian Bamboo 5.4.2
Atlassian Bamboo 5.4.1
Atlassian Bamboo 5.1
Atlassian Bamboo 5.0.1
Atlassian Bamboo 5.0
Atlassian Bamboo 4.4.5
Atlassian Bamboo 4.4.4
Atlassian Bamboo 4.3.2
Atlassian Bamboo 4.3.1
Atlassian Bamboo 4.0
Atlassian Bamboo 3.4.5
Atlassian Bamboo 3.3.3
Atlassian Bamboo 3.3.2
Atlassian Bamboo 3.3
Atlassian Bamboo 3.0.3
Atlassian Bamboo 2.7
Atlassian Bamboo 2.6.3
Atlassian Bamboo 2.5.1
9.8
CVSSv3
CVE-2015-8360
An unspecified resource in Atlassian Bamboo prior to 5.9.9 and 5.10.x prior to 5.10.0 allows remote malicious users to execute arbitrary Java code via serialized data to the JMS port.
Atlassian Bamboo 3.2
Atlassian Bamboo 5.9.7
Atlassian Bamboo 5.9.4
Atlassian Bamboo 5.8.1
Atlassian Bamboo 5.8
Atlassian Bamboo 5.5
Atlassian Bamboo 5.4.2
Atlassian Bamboo 5.1
Atlassian Bamboo 5.0.1
Atlassian Bamboo 4.4.5
Atlassian Bamboo 4.4.4
Atlassian Bamboo 4.3.2
Atlassian Bamboo 4.3.1
Atlassian Bamboo 4.0
Atlassian Bamboo 3.4.5
Atlassian Bamboo 3.3.3
Atlassian Bamboo 3.3.2
Atlassian Bamboo 3.1
Atlassian Bamboo 3.0.3
Atlassian Bamboo 2.7
Atlassian Bamboo 2.6.3
Atlassian Bamboo 2.5.1
9.1
CVSSv3
CVE-2015-8361
Multiple unspecified services in Atlassian Bamboo prior to 5.9.9 and 5.10.x prior to 5.10.0 do not require authentication, which allows remote malicious users to obtain sensitive information, modify settings, or manage build agents via unknown vectors involving the JMS port.
Atlassian Bamboo 5.9.4
Atlassian Bamboo 5.9.3
Atlassian Bamboo 5.7.2
Atlassian Bamboo 5.7.1
Atlassian Bamboo 5.4.1
Atlassian Bamboo 5.4
Atlassian Bamboo 5.9.2
Atlassian Bamboo 5.9.1
Atlassian Bamboo 5.9
Atlassian Bamboo 5.7
Atlassian Bamboo 5.6.2
Atlassian Bamboo 5.3
Atlassian Bamboo 5.2.2
Atlassian Bamboo 5.0
Atlassian Bamboo 4.4.1
Atlassian Bamboo 4.4
Atlassian Bamboo 4.2
Atlassian Bamboo 4.1.2
Atlassian Bamboo 3.4.3
Atlassian Bamboo 3.4.2
Atlassian Bamboo 3.2.2
Atlassian Bamboo 3.2
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
hard-coded
CVE-2024-27202
NULL pointer dereference
CVE-2024-28075
CVE-2024-33608
CVE-2024-28889
CVE-2024-34572
template injection
CVE-2024-34351
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started