8.8
CVSSv3

CVE-2017-9514

Published: 12/10/2017 Updated: 03/10/2019
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Bamboo prior to 6.0.5, 6.1.x prior to 6.1.4, and 6.2.x prior to 6.2.1 had a REST endpoint that parsed a YAML file and did not sufficiently restrict which classes could be loaded. An attacker who can log in to Bamboo as a user is able to exploit this vulnerability to execute Java code of their choice on systems that have vulnerable versions of Bamboo.

Vulnerable Product Search on Vulmon Subscribe to Product

atlassian bamboo 6.0.4

atlassian bamboo 6.2.0

atlassian bamboo 6.1.0

atlassian bamboo 6.1.1

atlassian bamboo 6.0.1

atlassian bamboo 6.0.3

atlassian bamboo 6.0.0

atlassian bamboo 6.0.2