Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
bamboo vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-22516
This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 8.1.0, 8.2.0, 9.0.0, 9.1.0, 9.2.0, and 9.3.0 of Bamboo Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.5, allows an authenticated malicious user ...
Atlassian Bamboo
6.5
CVSSv2
CVE-2015-6576
Bamboo 2.2 prior to 5.8.5 and 5.9.x prior to 5.9.7 allows remote attackers with access to the Bamboo web interface to execute arbitrary Java code via an unspecified resource.
Atlassian Bamboo
3 Github repositories
3.5
CVSSv2
CVE-2017-18040
The viewDeploymentVersionCommits resource in Atlassian Bamboo before version 6.2.0 allows remote malicious users to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a release.
Atlassian Bamboo
3.5
CVSSv2
CVE-2017-18041
The viewDeploymentVersionJiraIssuesDialog resource in Atlassian Bamboo before version 6.2.0 allows remote malicious users to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a release.
Atlassian Bamboo
6.8
CVSSv2
CVE-2017-18042
The update user administration resource in Atlassian Bamboo before version 6.3.1 allows remote malicious users to modify user data including passwords via a Cross-site request forgery (CSRF) vulnerability.
Atlassian Bamboo
6.8
CVSSv2
CVE-2017-18080
The saveConfigureSecurity resource in Atlassian Bamboo before version 6.3.1 allows remote malicious users to modify security settings via a Cross-site request forgery (CSRF) vulnerability.
Atlassian Bamboo
4.3
CVSSv2
CVE-2017-18081
The signupUser resource in Atlassian Bamboo before version 6.3.1 allows remote malicious users to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the value of the csrf token cookie.
Atlassian Bamboo
3.5
CVSSv2
CVE-2017-18082
The plan configure branches resource in Atlassian Bamboo before version 6.2.3 allows remote malicious users to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a branch.
Atlassian Bamboo
5
CVSSv2
CVE-2021-26067
Affected versions of Atlassian Bamboo allow an unauthenticated remote malicious user to view a stack trace that may reveal the path for the home directory in disk and if certain files exists on the tmp directory, via a Sensitive Data Exposure vulnerability in the /chart endpoint....
Atlassian Bamboo
6.8
CVSSv2
CVE-2017-14589
It was possible for double OGNL evaluation in FreeMarker templates through Struts FreeMarker tags to occur. An attacker who has restricted administration rights to Bamboo or who hosts a website that a Bamboo administrator visits, is able to exploit this vulnerability to execute J...
Atlassian Bamboo
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
blind SQL injection
SSRF
buffer overflow
CVE-2023-28952
CVE-2023-41822
CVE-2024-27956
CVE-2023-7028
CVE-2024-34447
CVE-2024-34460
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »