Bamboo
Atlassian · 27 CVEs
This High severity Improper Authorization vulnerability was introduced in versions 10.0.0, 10.1.0, 10.2.0, 11.0.0, 12.0…
Aug 18, 2026
This Critical severity OS Command Injection vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.…
Apr 21, 2026
This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0,…
Mar 17, 2026
This High severity RCE (Remote Code Execution) vulnerability CVE-2024-21689 was introduced in versions 9.1.0, 9.2.0, 9.…
Aug 20, 2024
This High severity File Inclusion vulnerability was introduced in versions 9.0.0, 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0 and…
Jul 16, 2024
This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 8.1.0, 8.2.0, 9.0.0, 9.1.0, 9.2…
Nov 21, 2023
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Fi…
Jul 20, 2022
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used…
Jul 20, 2022
Affected versions of Atlassian Bamboo allow an unauthenticated remote attacker to view a stack trace that may reveal th…
Jan 28, 2021
The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate…
Nov 8, 2019
Bamboo did not correctly check if a configured Mercurial repository URI contained values that the Windows operating sys…
Mar 29, 2018
The plan configure branches resource in Atlassian Bamboo before version 6.2.3 allows remote attackers to inject arbitra…
Feb 2, 2018
The signupUser resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to inject arbitrary HTML or Ja…
Feb 2, 2018
The saveConfigureSecurity resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to modify security…
Feb 2, 2018
The update user administration resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to modify user…
Feb 2, 2018
The viewDeploymentVersionJiraIssuesDialog resource in Atlassian Bamboo before version 6.2.0 allows remote attackers to…
Feb 2, 2018
The viewDeploymentVersionCommits resource in Atlassian Bamboo before version 6.2.0 allows remote attackers to inject ar…
Feb 2, 2018
Bamboo did not check that the name of a branch in a Mercurial repository contained argument parameters. An attacker who…
Dec 13, 2017
It was possible for double OGNL evaluation in FreeMarker templates through Struts FreeMarker tags to occur. An attacker…
Dec 13, 2017
Bamboo before 6.0.5, 6.1.x before 6.1.4, and 6.2.x before 6.2.1 had a REST endpoint that parsed a YAML file and did not…
Oct 12, 2017
Bamboo 2.2 before 5.8.5 and 5.9.x before 5.9.7 allows remote attackers with access to the Bamboo web interface to execu…
Oct 2, 2017
Atlassian Bamboo 5.x before 5.15.7 and 6.x before 6.0.1 did not correctly check if a user creating a deployment project…
Jun 14, 2017
Atlassian Bamboo before 5.11.4.1 and 5.12.x before 5.12.3.1 does not properly restrict permitted deserialized classes,…
Aug 2, 2016
Multiple unspecified services in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 do not require authentication,…
Feb 8, 2016
An unspecified resource in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 allows remote attackers to execute ar…
Feb 8, 2016
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-21584 | This High severity Improper Authorization vulnerability was introduced in versions 10.0.0, 10.1.0, 10.2.0, 11.0.0, 12.0.0, and 12.1.0 of Bamboo Data Center. Th… | HIGH | 0.31% | Aug 18, 2026 |
| CVE-2026-21571 | This Critical severity OS Command Injection vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 12.1.0 of Bambo… | CRITICAL | 1.34% | Apr 21, 2026 |
| CVE-2026-21570 | This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 12.1.0 of Ba… | HIGH | 0.57% | Mar 17, 2026 |
| CVE-2024-21689 | This High severity RCE (Remote Code Execution) vulnerability CVE-2024-21689 was introduced in versions 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0, and 9.6.0 of Bamboo D… | HIGH | 2.67% | Aug 20, 2024 |
| CVE-2024-21687 | This High severity File Inclusion vulnerability was introduced in versions 9.0.0, 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0 and 9.6.0 of Bamboo Data Center and Server.… | HIGH | 0.75% | Jul 16, 2024 |
| CVE-2023-22516 | This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 8.1.0, 8.2.0, 9.0.0, 9.1.0, 9.2.0, and 9.3.0 of Bamboo Data Center and… | HIGH | 1.22% | Nov 21, 2023 |
| CVE-2022-26137 | A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application… | HIGH | 2.41% | Jul 20, 2022 |
| CVE-2022-26136 | A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impa… | CRITICAL | 5.51% | Jul 20, 2022 |
| CVE-2021-26067 | Affected versions of Atlassian Bamboo allow an unauthenticated remote attacker to view a stack trace that may reveal the path for the home directory in disk an… | MEDIUM | 1.11% | Jan 28, 2021 |
| CVE-2019-15005 | The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results… | MEDIUM | 1.33% | Nov 8, 2019 |
| CVE-2018-5224 | Bamboo did not correctly check if a configured Mercurial repository URI contained values that the Windows operating system may consider argument parameters. An… | HIGH | 2.67% | Mar 29, 2018 |
| CVE-2017-18082 | The plan configure branches resource in Atlassian Bamboo before version 6.2.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site s… | MEDIUM | 0.58% | Feb 2, 2018 |
| CVE-2017-18081 | The signupUser resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS… | MEDIUM | 0.81% | Feb 2, 2018 |
| CVE-2017-18080 | The saveConfigureSecurity resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to modify security settings via a Cross-site request forger… | HIGH | 0.54% | Feb 2, 2018 |
| CVE-2017-18042 | The update user administration resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to modify user data including passwords via a Cross-si… | HIGH | 0.66% | Feb 2, 2018 |
| CVE-2017-18041 | The viewDeploymentVersionJiraIssuesDialog resource in Atlassian Bamboo before version 6.2.0 allows remote attackers to inject arbitrary HTML or JavaScript via… | MEDIUM | 0.61% | Feb 2, 2018 |
| CVE-2017-18040 | The viewDeploymentVersionCommits resource in Atlassian Bamboo before version 6.2.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross s… | MEDIUM | 0.61% | Feb 2, 2018 |
| CVE-2017-14590 | Bamboo did not check that the name of a branch in a Mercurial repository contained argument parameters. An attacker who has permission to create a repository i… | CRITICAL | 2.40% | Dec 13, 2017 |
| CVE-2017-14589 | It was possible for double OGNL evaluation in FreeMarker templates through Struts FreeMarker tags to occur. An attacker who has restricted administration right… | CRITICAL | 1.87% | Dec 13, 2017 |
| CVE-2017-9514 | Bamboo before 6.0.5, 6.1.x before 6.1.4, and 6.2.x before 6.2.1 had a REST endpoint that parsed a YAML file and did not sufficiently restrict which classes cou… | HIGH | 1.05% | Oct 12, 2017 |
| CVE-2015-6576 | Bamboo 2.2 before 5.8.5 and 5.9.x before 5.9.7 allows remote attackers with access to the Bamboo web interface to execute arbitrary Java code via an unspecifie… | HIGH | 3.67% | Oct 2, 2017 |
| CVE-2017-8907 | Atlassian Bamboo 5.x before 5.15.7 and 6.x before 6.0.1 did not correctly check if a user creating a deployment project had the edit permission and therefore t… | HIGH | 1.67% | Jun 14, 2017 |
| CVE-2016-5229 | Atlassian Bamboo before 5.11.4.1 and 5.12.x before 5.12.3.1 does not properly restrict permitted deserialized classes, which allows remote attackers to execute… | CRITICAL | 7.09% | Aug 2, 2016 |
| CVE-2015-8361 | Multiple unspecified services in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 do not require authentication, which allows remote attackers to obtain… | CRITICAL | 2.84% | Feb 8, 2016 |
| CVE-2015-8360 | An unspecified resource in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 allows remote attackers to execute arbitrary Java code via serialized data to… | CRITICAL | 2.98% | Feb 8, 2016 |
Showing 1 to 25 of 27 CVEs