CVE-2017-9514

EUVD-2017-18446
Bamboo before 6.0.5, 6.1.x before 6.1.4, and 6.2.x before 6.2.1 had a REST endpoint that parsed a YAML file and did not sufficiently restrict which classes could be loaded. An attacker who can log in to Bamboo as a user is able to exploit this vulnerability to execute Java code of their choice on systems that have vulnerable versions of Bamboo.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 53%
Affected Products (NVD)
VendorProductVersion
atlassianbamboo
6.0.0
atlassianbamboo
6.0.1
atlassianbamboo
6.0.2
atlassianbamboo
6.0.3
atlassianbamboo
6.0.4
atlassianbamboo
6.1.0
atlassianbamboo
6.1.1
atlassianbamboo
6.2.0
𝑥
= Vulnerable software versions