CVE-2017-14589 describes a critical vulnerability in Atlassian Bamboo, affecting versions prior to 6.1.6 and 6.2.0 through 6.2.4. This flaw allows for double OGNL evaluation within FreeMarker templates via Struts FreeMarker tags, enabling an attacker with restricted administration rights or through a malicious website to execute arbitrary Java code on the Bamboo server. The vulnerability carries a CVSS score of 9.6 (CRITICAL), indicating a severe impact with high confidentiality, integrity, and availability risks. It can be exploited over the network with low attack complexity, though user interaction is required. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. The vulnerability has also received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.1.6CPE matchmatch criteria | cpe:2.3:a:atlassian:bamboo:*:*:*:*:*:*:*:* | ||
>= 6.2.0, < 6.2.5CPE matchmatch criteria | cpe:2.3:a:atlassian:bamboo:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.