<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Bamboo (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/bamboo.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/bamboo-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Bamboo (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:55 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-21571 – This Critical severity OS Command Injection vulnerability was introduced in vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21571</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21571</guid>
    <pubDate>Tue, 21 Apr 2026 17:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-21571</strong></p>
  <p>This Critical severity OS Command Injection vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 12.1.0 of Bamboo Data Center.   This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 9.4 and a CVSS Vector of CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H allows an authenticated attacker to execute commands on the…</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21571">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-21570 – This High severity RCE (Remote Code Execution)  vulnerability was introduced in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21570</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21570</guid>
    <pubDate>Tue, 17 Mar 2026 18:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-21570</strong></p>
  <p>This High severity RCE (Remote Code Execution)  vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 12.1.0 of Bamboo Data Center.  This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.6, allows an authenticated attacker to execute malicious code on the remote system.  Atlassian recommends that Bamboo Data Center customers upgra…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21570">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-21689 – This High severity RCE (Remote Code Execution) vulnerability CVE-2024-21689  was...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21689</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21689</guid>
    <pubDate>Tue, 20 Aug 2024 10:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-21689</strong></p>
  <p>This High severity RCE (Remote Code Execution) vulnerability CVE-2024-21689  was introduced in versions 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0, and 9.6.0 of Bamboo Data Center and Server.  This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.6, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21689">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-21687 – This High severity File Inclusion vulnerability was introduced in versions 9.0.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21687</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21687</guid>
    <pubDate>Tue, 16 Jul 2024 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-21687</strong></p>
  <p>This High severity File Inclusion vulnerability was introduced in versions 9.0.0, 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0 and 9.6.0 of Bamboo Data Center and Server.  This File Inclusion vulnerability, with a CVSS Score of 8.1, allows an authenticated attacker to get the application to display the contents of a local file, or execute a different files already stored locally on the server which has high…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21687">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-22516 – This High severity RCE (Remote Code Execution) vulnerability was introduced in v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22516</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22516</guid>
    <pubDate>Tue, 21 Nov 2023 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-22516</strong></p>
  <p>This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 8.1.0, 8.2.0, 9.0.0, 9.1.0, 9.2.0, and 9.3.0 of Bamboo Data Center and Server.  This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.5, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability,…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22516">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-22506 – This High severity Injection and RCE (Remote Code Execution) vulnerability known...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22506</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22506</guid>
    <pubDate>Wed, 19 Jul 2023 00:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-22506</strong></p>
  <p>This High severity Injection and RCE (Remote Code Execution) vulnerability known as CVE-2023-22506 was introduced in version 8.0.0 of Bamboo Data Center.    This Injection and RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.5, allows an authenticated attacker to modify the actions taken by a system call and execute arbitrary code which has high impact to confidentiality, high im…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22506">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-26137 – A vulnerability in multiple Atlassian products allows a remote, unauthenticated ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-26137</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-26137</guid>
    <pubDate>Wed, 20 Jul 2022 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-26137</strong></p>
  <p>A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security issue associated with this vulnerability: Cross-origin resource sharing (CORS) bypass. Sending a specially crafted HTTP request can invoke the Servl…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-180</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-26137">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-26136 – A vulnerability in multiple Atlassian products allows a remote, unauthenticated ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-26136</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-26136</guid>
    <pubDate>Wed, 20 Jul 2022 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-26136</strong></p>
  <p>A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulnerability can result in authentication bypass and cross-site scripting. Atlassian has released updates that fix the root cause of this vulnerability, b…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-180</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-26136">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-37843 – The resolution SAML SSO apps for Atlassian products allow a remote attacker to l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-37843</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-37843</guid>
    <pubDate>Mon, 02 Aug 2021 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-37843</strong></p>
  <p>The resolution SAML SSO apps for Atlassian products allow a remote attacker to login to a user account when only the username is known (i.e., no other authentication is provided). The fixed versions are for Jira: 3.6.6.1, 4.0.12, 5.0.5; for Confluence 3.6.6, 4.0.12, 5.0.5; for Bitbucket 2.5.9, 3.6.6, 4.0.12, 5.0.5; for Bamboo 2.5.9, 3.6.6, 4.0.12, 5.0.5; and for Fisheye 2.5.9.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-37843">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-13347 – An issue was discovered in the SAML Single Sign On (SSO) plugin for several Atla...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-13347</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-13347</guid>
    <pubDate>Fri, 13 Dec 2019 13:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-13347</strong></p>
  <p>An issue was discovered in the SAML Single Sign On (SSO) plugin for several Atlassian products affecting versions 3.1.0 through 3.2.2 for Jira and Confluence, versions 2.4.0 through 3.0.3 for Bitbucket, and versions 2.4.0 through 2.5.2 for Bamboo. It allows locally disabled users to reactivate their accounts just by browsing the affected Jira/Confluence/Bitbucket/Bamboo instance, even when the ap…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-13347">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-5224 – Bamboo did not correctly check if a configured Mercurial repository URI containe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-5224</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-5224</guid>
    <pubDate>Thu, 29 Mar 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-5224</strong></p>
  <p>Bamboo did not correctly check if a configured Mercurial repository URI contained values that the Windows operating system may consider argument parameters. An attacker who has permission to create a repository in Bamboo, edit an existing plan in Bamboo that has a non-linked Mercurial repository, or create a plan in Bamboo either globally or in a project using Bamboo Specs can can execute code of…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-5224">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-18080 – The saveConfigureSecurity resource in Atlassian Bamboo before version 6.3.1 allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-18080</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-18080</guid>
    <pubDate>Fri, 02 Feb 2018 14:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-18080</strong></p>
  <p>The saveConfigureSecurity resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to modify security settings via a Cross-site request forgery (CSRF) vulnerability.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-18080">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-18042 – The update user administration resource in Atlassian Bamboo before version 6.3.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-18042</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-18042</guid>
    <pubDate>Fri, 02 Feb 2018 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-18042</strong></p>
  <p>The update user administration resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to modify user data including passwords via a Cross-site request forgery (CSRF) vulnerability.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-18042">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-14590 – Bamboo did not check that the name of a branch in a Mercurial repository contain...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-14590</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-14590</guid>
    <pubDate>Wed, 13 Dec 2017 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-14590</strong></p>
  <p>Bamboo did not check that the name of a branch in a Mercurial repository contained argument parameters. An attacker who has permission to create a repository in Bamboo, edit an existing plan that has a non-linked Mercurialrepository, create or edit a plan when there is at least one linked Mercurial repository that the attacker has permission to use, or commit to a Mercurial repository used by a B…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-14590">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-14589 – It was possible for double OGNL evaluation in FreeMarker templates through Strut...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-14589</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-14589</guid>
    <pubDate>Wed, 13 Dec 2017 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-14589</strong></p>
  <p>It was possible for double OGNL evaluation in FreeMarker templates through Struts FreeMarker tags to occur. An attacker who has restricted administration rights to Bamboo or who hosts a website that a Bamboo administrator visits, is able to exploit this vulnerability to execute Java code of their choice on systems that run a vulnerable version of Bamboo. All versions of Bamboo before 6.1.6 (the f…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-14589">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-9514 – Bamboo before 6.0.5, 6.1.x before 6.1.4, and 6.2.x before 6.2.1 had a REST endpo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-9514</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-9514</guid>
    <pubDate>Thu, 12 Oct 2017 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-9514</strong></p>
  <p>Bamboo before 6.0.5, 6.1.x before 6.1.4, and 6.2.x before 6.2.1 had a REST endpoint that parsed a YAML file and did not sufficiently restrict which classes could be loaded. An attacker who can log in to Bamboo as a user is able to exploit this vulnerability to execute Java code of their choice on systems that have vulnerable versions of Bamboo.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-9514">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-6576 – Bamboo 2.2 before 5.8.5 and 5.9.x before 5.9.7 allows remote attackers with acce...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-6576</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-6576</guid>
    <pubDate>Tue, 03 Oct 2017 01:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-6576</strong></p>
  <p>Bamboo 2.2 before 5.8.5 and 5.9.x before 5.9.7 allows remote attackers with access to the Bamboo web interface to execute arbitrary Java code via an unspecified resource.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-6576">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-8907 – Atlassian Bamboo 5.x before 5.15.7 and 6.x before 6.0.1 did not correctly check ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-8907</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-8907</guid>
    <pubDate>Wed, 14 Jun 2017 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-8907</strong></p>
  <p>Atlassian Bamboo 5.x before 5.15.7 and 6.x before 6.0.1 did not correctly check if a user creating a deployment project had the edit permission and therefore the rights to do so.  An attacker who can login to Bamboo as a user without the edit permission for deployment projects is able to use this vulnerability, provided there is an existing plan with a green build, to create a deployment project…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-8907">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-5229 – Atlassian Bamboo before 5.11.4.1 and 5.12.x before 5.12.3.1 does not properly re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-5229</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-5229</guid>
    <pubDate>Tue, 02 Aug 2016 16:59:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-5229</strong></p>
  <p>Atlassian Bamboo before 5.11.4.1 and 5.12.x before 5.12.3.1 does not properly restrict permitted deserialized classes, which allows remote attackers to execute arbitrary code via vectors related to XStream Serialization.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5229">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2015-8361 – Multiple unspecified services in Atlassian Bamboo before 5.9.9 and 5.10.x before...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-8361</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-8361</guid>
    <pubDate>Mon, 08 Feb 2016 19:59:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2015-8361</strong></p>
  <p>Multiple unspecified services in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 do not require authentication, which allows remote attackers to obtain sensitive information, modify settings, or manage build agents via unknown vectors involving the JMS port.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-8361">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2015-8360 – An unspecified resource in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-8360</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-8360</guid>
    <pubDate>Mon, 08 Feb 2016 19:59:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2015-8360</strong></p>
  <p>An unspecified resource in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 allows remote attackers to execute arbitrary Java code via serialized data to the JMS port.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-8360">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2014-9757 – The Ignite Realtime Smack XMPP API, as used in Atlassian Bamboo before 5.9.9 and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-9757</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-9757</guid>
    <pubDate>Mon, 08 Feb 2016 19:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2014-9757</strong></p>
  <p>The Ignite Realtime Smack XMPP API, as used in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0, allows remote configured XMPP servers to execute arbitrary Java code via serialized data in an XMPP message.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-9757">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2012-2926 – Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-2926</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-2926</guid>
    <pubDate>Tue, 22 May 2012 15:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2012-2926</strong></p>
  <p>Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 before 2.6.8, and 2.7 before 2.7.12; Bamboo before 3.3.4 and 3.4.x before 3.4.5; and Crowd before 2.0.9, 2.1 before 2.1.2, 2.2 before 2.2.9, 2.3 before 2.3.7, and 2.4 before 2.4.1 do not properly restrict the capabilities of third-party XML parsers, which allows r…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-2926">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
