Atlassian Bamboo 5.x before 5.15.7 and 6.x before 6.0.1 did not correctly check if a user creating a deployment project had the edit permission and therefore the rights to do so
Published Jun 14, 2017
8.8
HIGHCVSS 3.1
EPSS 1.67%
Description
Atlassian Bamboo 5.x before 5.15.7 and 6.x before 6.0.1 did not correctly check if a user creating a deployment project had the edit permission and therefore the rights to do so. An attacker who can login to Bamboo as a user without the edit permission for deployment projects is able to use this vulnerability, provided there is an existing plan with a green build, to create a deployment project and execute arbitrary code on an available Bamboo Agent. By default a local agent is enabled; this means that code execution can occur on the system hosting Bamboo as the user running Bamboo.
Affected products
-
- Version 5.0.0 <= version < 5.15.7StatusaffectedConstraints-
- Version 6.0.0 <= version < 6.0.1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Atlassian | Atlassian Bamboo | n/a |
|
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0.1
- 5.1
- 5.1.1
- 5.2
- 5.2.1
- 5.2.2
- 5.3
- 5.4
- 5.4.1
- 5.4.2
- 5.5
- 5.6
- 5.6.1
- 5.6.2
- 5.7
- 5.7.1
- 5.7.2
- 5.8
- 5.8.1
- 5.8.2
- 5.8.5
- 5.9
- 5.9.1
- 5.9.2
- 5.9.3
- 5.9.4
- 5.9.7
- 5.11.3
- 5.12.0
- 5.12.1
- 5.12.2
- 5.12.4
- 5.12.5
- 5.13.0
- 5.13.1
- 5.13.2
- 5.14.0
- 5.14.1
- 5.14.2
- 5.14.3
- 5.14.4.1
- 5.14.5
- 5.15.0
- 5.15.2
- 5.15.3
- 5.15.4
- 5.15.5
- 6.0.0
-
- Version 0StatusaffectedConstraints-
- Version
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AV:N/AC:L/Au:S/C:P/I:P/A:P
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Oct 16, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (8 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.67% (0.01669) | 75.92th | v5 (v2026.06.15) |
| Sep 20, 2026 | 1.67% (0.01669) | 75.74th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.11% (0.00115) | 45.68th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.12% (0.00118) | 44.05th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.58% (0.01578) | 75.39th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.44% (0.01440) | 50.53th | v2 (v2022.01.01) |
| Feb 3, 2022 | 1.09% (0.01095) | 29.04th | v5 (v2026.06.15) |
| Apr 14, 2021 | 1.09% (0.01095) | 0.00th | v1 |
References (2)
- http://www.securityfocus.com/bid/99090 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://confluence.atlassian.com/bamboo/bamboo-security-advisory-2017-06-14-907283498.html x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/99090 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://confluence.atlassian.com/bamboo/bamboo-security-advisory-2017-06-14-907283498.html | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.