-
Bug
-
Resolution: Fixed
-
High
-
None
-
None
-
Severity 2 - Major
-
The update user administration resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to modify user data including passwords via a Cross-site request forgery (CSRF) vulnerability.
This is an independent assessment and you should evaluate its applicability to your own IT environment.
CVSS v3 score: 8.1 => High severity
Exploitability Metrics
Scope Metric
Impact Metrics
https://asecurityteam.bitbucket.io/cvss_v3/#CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N