Multiple unspecified services in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 do not require authentication, which allows remote attackers to obtain sensitive information, modify settings, or manage build agents via unknown vectors involving the JMS port.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 02:38
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.com/files/135352/Bamboo-Deserialization-Missing-Authentication-Checks.html - | |
References | () http://www.securityfocus.com/archive/1/537347/100/0/threaded - | |
References | () https://confluence.atlassian.com/bamboo/bamboo-security-advisory-2016-01-20-794376535.html - Vendor Advisory | |
References | () https://jira.atlassian.com/browse/BAM-17102 - Patch, Vendor Advisory |
Information
Published : 2016-02-08 19:59
Updated : 2024-11-21 02:38
NVD link : CVE-2015-8361
Mitre link : CVE-2015-8361
CVE.ORG link : CVE-2015-8361
JSON object : View
Products Affected
atlassian
- bamboo
CWE
CWE-284
Improper Access Control