CVE-2015-6576: Code Injection
Published Oct 2, 2017
·Updated
Bamboo 2.2 before 5.8.5 and 5.9.x before 5.9.7 allows remote attackers with access to the Bamboo web interface to execute arbitrary Java code via an unspecified resource.
Affected Software
2 affected components
Atlassian Bamboo>=2.2<5.8.5
Atlassian Bamboo>=5.9<5.9.7
Event History
Oct 2, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-6576?
CVE-2015-6576 has a high severity level due to its potential to allow remote code execution.
2
How do I fix CVE-2015-6576?
To fix CVE-2015-6576, upgrade to Bamboo version 5.8.5 or 5.9.7 and later.
3
Who is affected by CVE-2015-6576?
CVE-2015-6576 affects Atlassian Bamboo versions 2.2 through 5.8.5 and 5.9.0 through 5.9.6.
4
What types of attacks can be executed using CVE-2015-6576?
CVE-2015-6576 allows attackers to execute arbitrary Java code remotely through the Bamboo web interface.
5
Is CVE-2015-6576 still a risk if I am running a patched version of Bamboo?
If you are running a patched version, the risk from CVE-2015-6576 is mitigated, but it's always advisable to stay updated on security practices.