[{"advisory":{"name":"Bamboo Security Advisory 2017-12-13","url":"https://confluence.atlassian.com/bamboo/bamboo-security-advisory-2017-12-13-939939816.html"},"cveId":"CVE-2017-14589","description":"It was possible for double OGNL evaluation in FreeMarker templates through Struts FreeMarker tags to occur. An attacker who has restricted administration rights to Bamboo or who hosts a website that a Bamboo administrator visits, is able to exploit this vulnerability to execute Java code of their choice on systems that run a vulnerable version of Bamboo. All versions of Bamboo before 6.1.6 (the fixed version for 6.1.x) and from 6.2.0 before 6.2.5 (the fixed version for 6.2.x) are affected by this vulnerability.","baseScore":9.6,"cpeMatches":[{"versionStartIncluding":null,"versionEndExcluding":"6.1.6"},{"versionStartIncluding":"6.2.0","versionEndExcluding":"6.2.5"}]},{"advisory":{"name":"Bamboo Security Advisory 2017-12-13","url":"https://confluence.atlassian.com/bamboo/bamboo-security-advisory-2017-12-13-939939816.html"},"cveId":"CVE-2017-14590","description":"Bamboo did not check that the name of a branch in a Mercurial repository contained argument parameters. An attacker who has permission to create a repository in Bamboo, edit an existing plan that has a non-linked Mercurialrepository, create or edit a plan when there is at least one linked Mercurial repository that the attacker has permission to use, or commit to a Mercurial repository used by a Bamboo plan which has branch detection enabled can execute code of their choice on systems that run a vulnerable version of Bamboo Server. Versions of Bamboo starting with 2.7.0 before 6.1.6 (the fixed version for 6.1.x) and from 6.2.0 before 6.2.5 (the fixed version for 6.2.x) are affected by this vulnerability.","baseScore":9.1,"cpeMatches":[{"versionStartIncluding":"2.7.0","versionEndExcluding":"6.1.6"},{"versionStartIncluding":"6.2.0","versionEndExcluding":"6.2.5"}]},{"advisory":{"name":"Bamboo Security Advisory 2017-10-11","url":"https://confluence.atlassian.com/bamboo/bamboo-security-advisory-2017-10-11-938843921.html"},"cveId":"CVE-2017-9514","description":"Bamboo before 6.0.5, 6.1.x before 6.1.4, and 6.2.x before 6.2.1 had a REST endpoint that parsed a YAML file and did not sufficiently restrict which classes could be loaded. An attacker who can log in to Bamboo as a user is able to exploit this vulnerability to execute Java code of their choice on systems that have vulnerable versions of Bamboo.","baseScore":8.8,"cpeMatches":[{"versionStartIncluding":"6.0.0","versionEndExcluding":"6.0.5"},{"versionStartIncluding":"6.1.0","versionEndExcluding":"6.1.4"}]},{"advisory":{"name":"Bamboo Security Advisory 2018-03-28","url":"https://confluence.atlassian.com/x/PS9sO"},"cveId":"CVE-2018-5224","description":"Bamboo did not correctly check if a configured Mercurial repository URI contained values that the Windows operating system may consider argument parameters. An attacker who has permission to create a repository in Bamboo, edit an existing plan in Bamboo that has a non-linked Mercurial repository, or create a plan in Bamboo either globally or in a project using Bamboo Specs can can execute code of their choice on systems that run a vulnerable version of Bamboo on the Windows operating system. All versions of Bamboo starting with 2.7.0 before 6.3.3 (the fixed version for 6.3.x) and from version 6.4.0 before 6.4.1 (the fixed version for 6.4.x) running on the Windows operating system are affected by this vulnerability.","baseScore":8.8,"cpeMatches":[{"versionStartIncluding":"2.7.0","versionEndExcluding":"6.3.3"},{"versionStartIncluding":"6.4.0","versionEndExcluding":"6.4.1"}]},{"advisory":{"name":"Bamboo Security Advisory 2021-04-07","url":"https://confluence.atlassian.com/bamboo/bamboo-security-advisory-2021-04-07-1047552896.html"},"cveId":"CVE-2020-27955","description":"Git LFS 2.12.0 allows Remote Code Execution.","baseScore":9.8,"cpeMatches":[{"versionStartIncluding":null,"versionEndExcluding":"7.2.3"}]},{"advisory":{"name":"Bamboo Security Advisory 2021-04-07","url":"https://confluence.atlassian.com/bamboo/bamboo-security-advisory-2021-04-07-1047552896.html"},"cveId":"CVE-2021-21237","description":"Git LFS is a command line extension for managing large files with Git. On Windows, if Git LFS operates on a malicious repository with a git.bat or git.exe file in the current directory, that program would be executed, permitting the attacker to execute arbitrary code. This does not affect Unix systems. This is the result of an incomplete fix for CVE-2020-27955. This issue occurs because on Windows, Go includes (and prefers) the current directory when the name of a command run does not contain a directory separator. Other than avoiding untrusted repositories or using a different operating system, there is no workaround. This is fixed in v2.13.2.","baseScore":7.8,"cpeMatches":[{"versionStartIncluding":null,"versionEndExcluding":"7.2.3"}]},{"advisory":{"name":"Multiple Products Security Advisory - Unrendered unicode bidirectional override characters - CVE-2021-42574","url":"https://confluence.atlassian.com/display/SECURITY/Multiple+Products+Security+Advisory+-+Unrendered+unicode+bidirectional+override+characters+-+CVE-2021-42574"},"cveId":"CVE-2021-42574","description":"An issue was discovered in the Bidirectional Algorithm in the Unicode Specification through 14.0. It permits the visual reordering of characters via control sequences, which can be used to craft source code that renders different logic than the logical ordering of tokens ingested by compilers and interpreters. Adversaries can leverage this to encode source code for compilers accepting Unicode such that targeted vulnerabilities are introduced invisibly to human reviewers. NOTE: the Unicode Consortium offers the following alternative approach to presenting this concern. An issue is noted in the nature of international text that can affect applications that implement support for The Unicode Standard and the Unicode Bidirectional Algorithm (all versions). Due to text display behavior when text includes left-to-right and right-to-left characters, the visual order of tokens may be different from their logical order. Additionally, control characters needed to fully support the requirements of bidirectional text can further obfuscate the logical order of tokens. Unless mitigated, an adversary could craft source code such that the ordering of tokens perceived by human reviewers does not match what will be processed by a compiler/interpreter/etc. The Unicode Consortium has documented this class of vulnerability in its document, Unicode Technical Report #36, Unicode Security Considerations. The Unicode Consortium also provides guidance on mitigations for this class of issues in Unicode Technical Standard #39, Unicode Security Mechanisms, and in Unicode Standard Annex #31, Unicode Identifier and Pattern Syntax. Also, the BIDI specification allows applications to tailor the implementation in ways that can mitigate misleading visual reordering in program text; see HL4 in Unicode Standard Annex #9, Unicode Bidirectional Algorithm.","baseScore":8.3,"cpeMatches":[{"versionStartIncluding":null,"versionEndExcluding":"8.0.4"}]},{"advisory":{"name":"Multiple Products Security Advisory - CVE-2022-26136, CVE-2022-26137","url":"https://confluence.atlassian.com/security/multiple-products-security-advisory-cve-2022-26136-cve-2022-26137-1141493031.html"},"cveId":"CVE-2022-26136","description":"A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulnerability can result in authentication bypass and cross-site scripting. Atlassian has released updates that fix the root cause of this vulnerability, but has not exhaustively enumerated all potential consequences of this vulnerability. Atlassian Bamboo versions are affected before 8.0.9, from 8.1.0 before 8.1.8, and from 8.2.0 before 8.2.4. Atlassian Bitbucket versions are affected before 7.6.16, from 7.7.0 before 7.17.8, from 7.18.0 before 7.19.5, from 7.20.0 before 7.20.2, from 7.21.0 before 7.21.2, and versions 8.0.0 and 8.1.0. Atlassian Confluence versions are affected before 7.4.17, from 7.5.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and version 7.21.0. Atlassian Crowd versions are affected before 4.3.8, from 4.4.0 before 4.4.2, and version 5.0.0. Atlassian Fisheye and Crucible versions before 4.8.10 are affected. Atlassian Jira versions are affected before 8.13.22, from 8.14.0 before 8.20.10, and from 8.21.0 before 8.22.4. Atlassian Jira Service Management versions are affected before 4.13.22, from 4.14.0 before 4.20.10, and from 4.21.0 before 4.22.4.","baseScore":9.8,"cpeMatches":[{"versionStartIncluding":null,"versionEndExcluding":"7.2.9"},{"versionStartIncluding":"8.0.0","versionEndExcluding":"8.0.9"},{"versionStartIncluding":"8.1.0","versionEndExcluding":"8.1.8"},{"versionStartIncluding":"8.2.0","versionEndExcluding":"8.2.4"}]},{"advisory":{"name":"Multiple Products Security Advisory - CVE-2022-26136, CVE-2022-26137","url":"https://confluence.atlassian.com/security/multiple-products-security-advisory-cve-2022-26136-cve-2022-26137-1141493031.html"},"cveId":"CVE-2022-26137","description":"A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security issue associated with this vulnerability: Cross-origin resource sharing (CORS) bypass. Sending a specially crafted HTTP request can invoke the Servlet Filter used to respond to CORS requests, resulting in a CORS bypass. An attacker that can trick a user into requesting a malicious URL can access the vulnerable application with the victim’s permissions. Atlassian Bamboo versions are affected before 8.0.9, from 8.1.0 before 8.1.8, and from 8.2.0 before 8.2.4. Atlassian Bitbucket versions are affected before 7.6.16, from 7.7.0 before 7.17.8, from 7.18.0 before 7.19.5, from 7.20.0 before 7.20.2, from 7.21.0 before 7.21.2, and versions 8.0.0 and 8.1.0. Atlassian Confluence versions are affected before 7.4.17, from 7.5.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and version 7.21.0. Atlassian Crowd versions are affected before 4.3.8, from 4.4.0 before 4.4.2, and version 5.0.0. Atlassian Fisheye and Crucible versions before 4.8.10 are affected. Atlassian Jira versions are affected before 8.13.22, from 8.14.0 before 8.20.10, and from 8.21.0 before 8.22.4. Atlassian Jira Service Management versions are affected before 4.13.22, from 4.14.0 before 4.20.10, and from 4.21.0 before 4.22.4.","baseScore":8.8,"cpeMatches":[{"versionStartIncluding":null,"versionEndExcluding":"7.2.9"},{"versionStartIncluding":"8.0.0","versionEndExcluding":"8.0.9"},{"versionStartIncluding":"8.1.0","versionEndExcluding":"8.1.8"},{"versionStartIncluding":"8.2.0","versionEndExcluding":"8.2.4"}]}]
