Uploaded image for project: 'Bamboo Data Center'
  1. Bamboo Data Center
  2. BAM-10028

XSS vulnerability in /agent/configureAgents resource

      We have identified and fixed a reflected cross-site scripting (XSS) vulnerability in the Bamboo configureAgents resource.

      This issue is reported in our security advisory on this page:
      https://confluence.atlassian.com/x/rQP5FQ

      You can read more about XSS attacks at:

      http://www.cgisecurity.com/xss-faq.html
      http://www.cert.org/advisories/CA-2000-02.html

            [BAM-10028] XSS vulnerability in /agent/configureAgents resource

            Monique Khairuliana (Inactive) made changes -
            Workflow Original: Bamboo Workflow 2016 v1 - Restricted [ 1435407 ] New: JAC Bug Workflow v3 [ 3379505 ]
            Status Original: Resolved [ 5 ] New: Closed [ 6 ]
            Owen made changes -
            Workflow Original: Bamboo Workflow 2016 v1 [ 1410106 ] New: Bamboo Workflow 2016 v1 - Restricted [ 1435407 ]
            Marek Went (Inactive) made changes -
            Workflow Original: Bamboo Workflow 2014 v2 [ 610384 ] New: Bamboo Workflow 2016 v1 [ 1410106 ]
            Security Metrics Bot made changes -
            Labels Original: advisory security New: advisory cvss-high security
            James Dumay made changes -
            Workflow Original: Bamboo Workflow 2014 [ 593053 ] New: Bamboo Workflow 2014 v2 [ 610384 ]
            James Dumay made changes -
            Workflow Original: Bamboo Workflow 2010 [ 351514 ] New: Bamboo Workflow 2014 [ 593053 ]
            David Black made changes -
            Description Original: We have identified and fixed a reflected cross-site scripting (XSS) vulnerability in the Bamboo configureAgents resource.

            This issue is reported in our security advisory on this page:
            http://confluence.atlassian.com/x/lwH6Dw

            You can read more about XSS attacks at:

                http://www.cgisecurity.com/xss-faq.html
                http://www.cert.org/advisories/CA-2000-02.html
            New: We have identified and fixed a reflected cross-site scripting (XSS) vulnerability in the Bamboo configureAgents resource.

            This issue is reported in our security advisory on this page:
            https://confluence.atlassian.com/x/rQP5FQ

            You can read more about XSS attacks at:

                http://www.cgisecurity.com/xss-faq.html
                http://www.cert.org/advisories/CA-2000-02.html
            paulwatson (Inactive) made changes -
            Security Original: Reporters and Developers [ 10070 ]
            VitalyA made changes -
            Labels New: advisory security
            VitalyA made changes -
            Description Original: We have identified and fixed a cross-site scripting (XSS) vulnerability in the Bamboo /agent/configureAgents resource.

            * An attacker might take advantage of the vulnerability to steal other users' session cookies or other credentials, by sending the credentials back to such an attacker's own web server.
            * An attacker's text and script might be displayed to other people viewing the Bamboo page. This is potentially damaging to your company's reputation.

            This issue is reported in our security advisory on this page:
            http://confluence.atlassian.com/x/lwH6Dw

            You can read more about XSS attacks at cgisecurity, CERT and other places on the web:

            * http://www.cgisecurity.com/xss-faq.html
            * http://www.cert.org/advisories/CA-2000-02.html

            New: We have identified and fixed a reflected cross-site scripting (XSS) vulnerability in the Bamboo configureAgents resource.

            This issue is reported in our security advisory on this page:
            http://confluence.atlassian.com/x/lwH6Dw

            You can read more about XSS attacks at:

                http://www.cgisecurity.com/xss-faq.html
                http://www.cert.org/advisories/CA-2000-02.html

              vosipov VitalyA
              pwatson paulwatson (Inactive)
              Affected customers:
              0 This affects my team
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: