Description
The plan configure branches resource in Atlassian Bamboo before version 6.2.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a branch.
Affected products
- Atlassian / Bambooprior to 6.2.3 – prior to 6.2.3