Deployment Project Permissions Flaw in Atlassian Bamboo
CVE-2017-8907
What is CVE-2017-8907?
Atlassian Bamboo versions 5.x prior to 5.15.7 and 6.x prior to 6.0.1 contain an improper authorization vulnerability. This flaw allows authenticated users lacking the necessary edit permissions for deployment projects to exploit the system. If such a user has access to an existing plan with a successful build, they can create a deployment project. This, in turn, enables them to execute arbitrary code on any Bamboo Agent that is available, as the default configuration allows for a local agent, leading to potential risks of compromise on the hosting system.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Atlassian Bamboo 5.0.0 <= version < 5.15.7 < 5.0.0 version 5.15.7
Atlassian Bamboo 6.0.0 <= version < 6.0.1 < 6.0.0 version 6.0.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved