CVE-2015-6576

Bamboo 2.2 before 5.8.5 and 5.9.x before 5.9.7 allows remote attackers with access to the Bamboo web interface to execute arbitrary Java code via an unspecified resource.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:atlassian:bamboo:*:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:bamboo:*:*:*:*:*:*:*:*

History

21 Nov 2024, 02:35

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/134065/Bamboo-Java-Code-Execution.html - Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/134065/Bamboo-Java-Code-Execution.html - Third Party Advisory, VDB Entry
References () http://www.securityfocus.com/archive/1/536747/100/0/threaded - Third Party Advisory, VDB Entry () http://www.securityfocus.com/archive/1/536747/100/0/threaded - Third Party Advisory, VDB Entry
References () https://confluence.atlassian.com/x/Hw7RLg - Vendor Advisory () https://confluence.atlassian.com/x/Hw7RLg - Vendor Advisory
References () https://jira.atlassian.com/browse/BAM-16439 - Issue Tracking, Vendor Advisory () https://jira.atlassian.com/browse/BAM-16439 - Issue Tracking, Vendor Advisory

Information

Published : 2017-10-03 01:29

Updated : 2024-11-21 02:35


NVD link : CVE-2015-6576

Mitre link : CVE-2015-6576

CVE.ORG link : CVE-2015-6576


JSON object : View

Products Affected

atlassian

  • bamboo
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')