CVE-2017-18042: CSRF
The update user administration resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to modify user data including passwords via a Cross-site request forgery (CSRF) vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-18042?
CVE-2017-18042 is a vulnerability in Atlassian Bamboo that allows remote attackers to modify user data including passwords via a Cross-site request forgery (CSRF) vulnerability.
What is the severity of CVE-2017-18042?
The severity of CVE-2017-18042 is high with a severity score of 8.8.
How does CVE-2017-18042 affect Atlassian Bamboo?
CVE-2017-18042 affects Atlassian Bamboo versions up to and excluding 6.3.1.
How can remote attackers exploit CVE-2017-18042?
Remote attackers can exploit CVE-2017-18042 by performing a Cross-site request forgery attack to modify user data, including passwords.
Are there any references for CVE-2017-18042?
Yes, you can find more information about CVE-2017-18042 at the following links: [SecurityFocus](http://www.securityfocus.com/bid/103110) and [Atlassian JIRA](https://jira.atlassian.com/browse/BAM-19663).