Code Execution Vulnerability in Bamboo Server by Atlassian
CVE-2017-14590
9.1CRITICAL
What is CVE-2017-14590?
An authorization flaw in Bamboo allows an attacker with appropriate repository permissions to execute arbitrary code on systems running vulnerable versions of the software. Specifically, the vulnerability arises from Bamboo's failure to validate branch names in a Mercurial repository, which could be exploited by someone who can create or modify plans that access these repositories. Versions affected include Bamboo Server from 2.7.0 up to, but not including, 6.1.6 and from 6.2.0 up to, but not including, 6.2.5.
Affected Version(s)
Bamboo from 2.7.0 before 6.1.6 (the fixed version for 6.1.x)
Bamboo from 6.2.0 before 6.2.5