CVE-2015-8361

critical

Description

Multiple unspecified services in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 do not require authentication, which allows remote attackers to obtain sensitive information, modify settings, or manage build agents via unknown vectors involving the JMS port.

References

https://jira.atlassian.com/browse/BAM-17102

https://confluence.atlassian.com/bamboo/bamboo-security-advisory-2016-01-20-794376535.html

http://www.securityfocus.com/archive/1/537347/100/0/threaded

http://packetstormsecurity.com/files/135352/Bamboo-Deserialization-Missing-Authentication-Checks.html

Details

Source: Mitre, NVD

Published: 2016-02-08

Updated: 2018-10-09

Risk Information

CVSS v2

Base Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 9.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Severity: Critical