CVE-2017-18081: XSS
Published Feb 2, 2018
·Updated
The signupUser resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the value of the csrf token cookie.
Affected Software
1 affected component
Atlassian Bamboo<6.3.1
Event History
Feb 2, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2017-18081.
2
What is the severity of CVE-2017-18081?
The severity of CVE-2017-18081 is medium.
3
How does CVE-2017-18081 affect Atlassian Bamboo?
CVE-2017-18081 affects Atlassian Bamboo versions up to and including 6.3.1.
4
What is the CWE ID for CVE-2017-18081?
The CWE ID for CVE-2017-18081 is CWE-79 and CWE-352.
5
How can I fix CVE-2017-18081 in Atlassian Bamboo?
To fix CVE-2017-18081 in Atlassian Bamboo, you should update to version 6.3.1 or later.