Arbitrary Code Execution Vulnerability in Bamboo by Atlassian
CVE-2018-5224
8.8HIGH
What is CVE-2018-5224?
An issue in Bamboo allowed improperly validated Mercurial repository URIs, permitting attackers with certain permissions to execute arbitrary code on affected Windows systems. This vulnerability impacts various versions of Bamboo, allowing exploitation through the creation or manipulation of repository configurations.
Affected Version(s)
Bamboo 2.7.1
Bamboo < 6.3.3
Bamboo 6.4.0