Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
atlassian bamboo vulnerabilities and exploits
(subscribe to this query)
580
VMScore
CVE-2015-6576
Bamboo 2.2 prior to 5.8.5 and 5.9.x prior to 5.9.7 allows remote attackers with access to the Bamboo web interface to execute arbitrary Java code via an unspecified resource.
Atlassian Bamboo
3 Github repositories
578
VMScore
CVE-2017-9514
Bamboo prior to 6.0.5, 6.1.x prior to 6.1.4, and 6.2.x prior to 6.2.1 had a REST endpoint that parsed a YAML file and did not sufficiently restrict which classes could be loaded. An attacker who can log in to Bamboo as a user is able to exploit this vulnerability to execute Java ...
Atlassian Bamboo 6.0.4
Atlassian Bamboo 6.2.0
Atlassian Bamboo 6.1.0
Atlassian Bamboo 6.1.1
Atlassian Bamboo 6.0.1
Atlassian Bamboo 6.0.3
Atlassian Bamboo 6.0.0
Atlassian Bamboo 6.0.2
578
VMScore
CVE-2017-8907
Atlassian Bamboo 5.x prior to 5.15.7 and 6.x prior to 6.0.1 did not correctly check if a user creating a deployment project had the edit permission and therefore the rights to do so. An attacker who can login to Bamboo as a user without the edit permission for deployment projects...
Atlassian Bamboo 6.0.0
Atlassian Bamboo 5.15.5
Atlassian Bamboo 5.15.3
Atlassian Bamboo 5.15.4
Atlassian Bamboo 5.3
Atlassian Bamboo 5.4
Atlassian Bamboo 5.4.1
Atlassian Bamboo 5.4.2
Atlassian Bamboo 5.9.2
Atlassian Bamboo 5.9.3
Atlassian Bamboo 5.9.4
Atlassian Bamboo 5.9.7
Atlassian Bamboo 5.14.2
Atlassian Bamboo 5.14.1
Atlassian Bamboo 5.13.0
Atlassian Bamboo 5.12.5
Atlassian Bamboo 5.15.0
Atlassian Bamboo 5.0
Atlassian Bamboo 5.2
Atlassian Bamboo 5.2.2
Atlassian Bamboo 5.5
Atlassian Bamboo 5.6.1
570
VMScore
CVE-2015-8361
Multiple unspecified services in Atlassian Bamboo prior to 5.9.9 and 5.10.x prior to 5.10.0 do not require authentication, which allows remote malicious users to obtain sensitive information, modify settings, or manage build agents via unknown vectors involving the JMS port.
Atlassian Bamboo 5.9.4
Atlassian Bamboo 5.9.3
Atlassian Bamboo 5.7.2
Atlassian Bamboo 5.7.1
Atlassian Bamboo 5.4.1
Atlassian Bamboo 5.4
Atlassian Bamboo 5.9.2
Atlassian Bamboo 5.9.1
Atlassian Bamboo 5.9
Atlassian Bamboo 5.7
Atlassian Bamboo 5.6.2
Atlassian Bamboo 5.3
Atlassian Bamboo 5.2.2
Atlassian Bamboo 5.0
Atlassian Bamboo 4.4.1
Atlassian Bamboo 4.4
Atlassian Bamboo 4.2
Atlassian Bamboo 4.1.2
Atlassian Bamboo 3.4.3
Atlassian Bamboo 3.4.2
Atlassian Bamboo 3.2.2
Atlassian Bamboo 3.2
534
VMScore
CVE-2019-13347
An issue exists in the SAML Single Sign On (SSO) plugin for several Atlassian products affecting versions 3.1.0 up to and including 3.2.2 for Jira and Confluence, versions 2.4.0 up to and including 3.0.3 for Bitbucket, and versions 2.4.0 up to and including 2.5.2 for Bamboo. It a...
Atlassian Saml Single Sign On
445
VMScore
CVE-2021-26067
Affected versions of Atlassian Bamboo allow an unauthenticated remote malicious user to view a stack trace that may reveal the path for the home directory in disk and if certain files exists on the tmp directory, via a Sensitive Data Exposure vulnerability in the /chart endpoint....
Atlassian Bamboo
383
VMScore
CVE-2017-18081
The signupUser resource in Atlassian Bamboo before version 6.3.1 allows remote malicious users to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the value of the csrf token cookie.
Atlassian Bamboo
356
VMScore
CVE-2019-15005
The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message may contain configuration infor...
Atlassian Troubleshooting And Support
Atlassian Bamboo
Atlassian Bitbucket
Atlassian Confluence
Atlassian Crowd
Atlassian Crucible
Atlassian Fisheye
Atlassian Jira
312
VMScore
CVE-2017-18040
The viewDeploymentVersionCommits resource in Atlassian Bamboo before version 6.2.0 allows remote malicious users to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a release.
Atlassian Bamboo
312
VMScore
CVE-2017-18041
The viewDeploymentVersionJiraIssuesDialog resource in Atlassian Bamboo before version 6.2.0 allows remote malicious users to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a release.
Atlassian Bamboo
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-52710
arbitrary
CVE-2024-5272
CVE-2024-2961
brute force
remote
CVE-2024-32944
CVE-2024-36241
CVE-2024-5274
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »