CVE-2015-6576: Atlassian Bamboo

High severity, CVSS 8.8. EPSS: 3.7% chance of exploitation in the next 30 days.

Bamboo 2.2 before 5.8.5 and 5.9.x before 5.9.7 allows remote attackers with access to the Bamboo web interface to execute arbitrary Java code via an unspecified resource.

Affected products

  • Atlassian Bamboo: from 2.2, before 5.8.5 (fixed in 5.8.5); from 5.9, before 5.9.7 (fixed in 5.9.7)

Published 2017-10-03. Last modified 2026-06-17.