Atlassian
Atlassian Bamboo: vulnerabilidades y CVE
Atlassian Bamboo tiene 27 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 9 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE27
Últimos 12 meses3
Críticas9
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-21584 | Alta (7.6) | 0.31% | — | 18 ago 2026 | This High severity Improper Authorization vulnerability was introduced in versions 10.0.0, 10.1.0, 10.2.0, 11.0.0, 12.0.0, and 12.1.0 of Bamboo Data Center. * Bamboo Data Center 10.2: Upgrade to a release greater than… |
| CVE-2026-21571 | Crítica (9.4) | 1.3% | — | 21 abr 2026 | This Critical severity OS Command Injection vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 12.1.0 of Bamboo Data Center. This RCE (Remote Code Execution)… |
| CVE-2026-21570 | Alta (8.6) | 0.57% | — | 17 mar 2026 | This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 12.1.0 of Bamboo Data Center. This RCE (Remote Code Execution)… |
| CVE-2024-21689 | Alta (8) | 2.7% | — | 20 ago 2024 | This High severity RCE (Remote Code Execution) vulnerability CVE-2024-21689 was introduced in versions 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0, and 9.6.0 of Bamboo Data Center and Server. This RCE (Remote Code Execution)… |
| CVE-2024-21687 | Alta (8.1) | 0.75% | — | 16 jul 2024 | This High severity File Inclusion vulnerability was introduced in versions 9.0.0, 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0 and 9.6.0 of Bamboo Data Center and Server. This File Inclusion vulnerability, with a CVSS Score of… |
| CVE-2023-22516 | Alta (8.8) | 1.2% | — | 21 nov 2023 | This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 8.1.0, 8.2.0, 9.0.0, 9.1.0, 9.2.0, and 9.3.0 of Bamboo Data Center and Server. This RCE (Remote Code Execution) vulnerability, with… |
| CVE-2022-26137 | Alta (8.8) | 2.3% | — | 20 jul 2022 | A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed… |
| CVE-2022-26136 | Crítica (9.8) | 5.4% | — | 20 jul 2022 | A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how… |
| CVE-2021-26067 | Media (5.3) | 1.1% | — | 28 ene 2021 | Affected versions of Atlassian Bamboo allow an unauthenticated remote attacker to view a stack trace that may reveal the path for the home directory in disk and if certain files exists on the tmp directory, via a… |
| CVE-2019-15005 | Media (4.3) | 1.3% | — | 8 nov 2019 | The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing… |
| CVE-2018-5224 | Alta (8.8) | 2.7% | — | 29 mar 2018 | Bamboo did not correctly check if a configured Mercurial repository URI contained values that the Windows operating system may consider argument parameters. An attacker who has permission to create a repository in… |
| CVE-2017-18082 | Media (5.4) | 0.58% | — | 2 feb 2018 | The plan configure branches resource in Atlassian Bamboo before version 6.2.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a branch. |
| CVE-2017-18081 | Media (6.1) | 0.81% | — | 2 feb 2018 | The signupUser resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the value of the csrf token cookie. |
| CVE-2017-18080 | Alta (8.8) | 0.54% | — | 2 feb 2018 | The saveConfigureSecurity resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to modify security settings via a Cross-site request forgery (CSRF) vulnerability. |
| CVE-2017-18042 | Alta (8.8) | 0.66% | — | 2 feb 2018 | The update user administration resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to modify user data including passwords via a Cross-site request forgery (CSRF) vulnerability. |
| CVE-2017-18041 | Media (5.4) | 0.61% | — | 2 feb 2018 | The viewDeploymentVersionJiraIssuesDialog resource in Atlassian Bamboo before version 6.2.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a… |
| CVE-2017-18040 | Media (5.4) | 0.61% | — | 2 feb 2018 | The viewDeploymentVersionCommits resource in Atlassian Bamboo before version 6.2.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a release. |
| CVE-2017-14590 | Crítica (9.1) | 2.4% | — | 13 dic 2017 | Bamboo did not check that the name of a branch in a Mercurial repository contained argument parameters. An attacker who has permission to create a repository in Bamboo, edit an existing plan that has a non-linked… |
| CVE-2017-14589 | Crítica (9.6) | 1.9% | — | 13 dic 2017 | It was possible for double OGNL evaluation in FreeMarker templates through Struts FreeMarker tags to occur. An attacker who has restricted administration rights to Bamboo or who hosts a website that a Bamboo… |
| CVE-2017-9514 | Alta (8.8) | 1.0% | — | 12 oct 2017 | Bamboo before 6.0.5, 6.1.x before 6.1.4, and 6.2.x before 6.2.1 had a REST endpoint that parsed a YAML file and did not sufficiently restrict which classes could be loaded. An attacker who can log in to Bamboo as a user… |
| CVE-2015-6576 | Alta (8.8) | 3.7% | — | 3 oct 2017 | Bamboo 2.2 before 5.8.5 and 5.9.x before 5.9.7 allows remote attackers with access to the Bamboo web interface to execute arbitrary Java code via an unspecified resource. |
| CVE-2017-8907 | Alta (8.8) | 1.7% | — | 14 jun 2017 | Atlassian Bamboo 5.x before 5.15.7 and 6.x before 6.0.1 did not correctly check if a user creating a deployment project had the edit permission and therefore the rights to do so. An attacker who can login to Bamboo as a… |
| CVE-2016-5229 | Crítica (9.8) | 7.1% | — | 2 ago 2016 | Atlassian Bamboo before 5.11.4.1 and 5.12.x before 5.12.3.1 does not properly restrict permitted deserialized classes, which allows remote attackers to execute arbitrary code via vectors related to XStream Serialization. |
| CVE-2015-8361 | Crítica (9.1) | 2.8% | — | 8 feb 2016 | Multiple unspecified services in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 do not require authentication, which allows remote attackers to obtain sensitive information, modify settings, or manage build… |
| CVE-2015-8360 | Crítica (9.8) | 3.0% | — | 8 feb 2016 | An unspecified resource in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 allows remote attackers to execute arbitrary Java code via serialized data to the JMS port. |
| CVE-2014-9757 | Crítica (9.8) | 2.3% | — | 8 feb 2016 | The Ignite Realtime Smack XMPP API, as used in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0, allows remote configured XMPP servers to execute arbitrary Java code via serialized data in an XMPP message. |
| CVE-2012-2926 | Crítica (9.1) | 66% | — | 22 may 2012 | Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 before 2.6.8, and 2.7 before 2.7.12; Bamboo before 3.3.4 and 3.4.x before 3.4.5; and… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.