Description
The update user administration resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to modify user data including passwords via a Cross-site request forgery (CSRF) vulnerability.
Affected products
- Atlassian / Bambooprior to 6.3.1 – prior to 6.3.1