Vulnerability Description
Bamboo 2.2 before 5.8.5 and 5.9.x before 5.9.7 allows remote attackers with access to the Bamboo web interface to execute arbitrary Java code via an unspecified resource.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Atlassian | Bamboo | >= 2.2, < 5.8.5 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/134065/Bamboo-Java-Code-Execution.htmlThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/archive/1/536747/100/0/threadedThird Party AdvisoryVDB Entry
- https://confluence.atlassian.com/x/Hw7RLgVendor Advisory
- https://jira.atlassian.com/browse/BAM-16439Issue TrackingVendor Advisory
- http://packetstormsecurity.com/files/134065/Bamboo-Java-Code-Execution.htmlThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/archive/1/536747/100/0/threadedThird Party AdvisoryVDB Entry
- https://confluence.atlassian.com/x/Hw7RLgVendor Advisory
- https://jira.atlassian.com/browse/BAM-16439Issue TrackingVendor Advisory
FAQ
What is CVE-2015-6576?
CVE-2015-6576 is a vulnerability with a CVSS score of 8.8 (HIGH). Bamboo 2.2 before 5.8.5 and 5.9.x before 5.9.7 allows remote attackers with access to the Bamboo web interface to execute arbitrary Java code via an unspecified resource.
How severe is CVE-2015-6576?
CVE-2015-6576 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-6576?
Check the references section above for vendor advisories and patch information. Affected products include: Atlassian Bamboo.