CVE-2017-18082: XSS
Published Feb 2, 2018
·Updated
The plan configure branches resource in Atlassian Bamboo before version 6.2.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a branch.
Affected Software
1 affected component
Atlassian Bamboo<6.2.3
Event History
Feb 2, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2017-18082.
2
What is the description of this vulnerability?
The vulnerability allows remote attackers to inject arbitrary HTML or JavaScript via a cross-site scripting (XSS) vulnerability through the name of a branch in Atlassian Bamboo before version 6.2.3.
3
What is the severity of CVE-2017-18082?
CVE-2017-18082 has a severity keyword of 'medium' and a severity value of 5.4.
4
How does CVE-2017-18082 affect Atlassian Bamboo?
CVE-2017-18082 affects Atlassian Bamboo before version 6.2.3.
5
How can I fix CVE-2017-18082?
To fix CVE-2017-18082, update Atlassian Bamboo to version 6.2.3 or later.