Security advisories
As a distributed application, Bamboo's application-level security is important. This document contains links to version-specific security advisories and related documents for the Bamboo application.
This document is intended to provide information to system administrators about the security of the Bamboo application. It does not describe Bamboo's internal security model – user management and permissions – except as it relates to the overall application security.
Finding and reporting a security vulnerability
Atlassian's channel for reporting security issues is detailed in How to Report a Security Issue.
Publication of Bamboo security advisories
Atlassian's approach to publishing security advisories is detailed in Security Advisory Publishing Policy.
You can subscribe to email alerts or modify the settings according to the guidelines in Subscribing to security advisories below.
Severity levels
Atlassian's scale for measuring security issues is detailed in Severity Levels for Security Issues.
Our patch policy
Atlassian's approach to releasing patches is detailed in our Security Patch Policy.
Subscribing to security advisories
You can configure Atlassian email notifications in your MyAtlassian account. We especially recommend subscribing to email alerts if you're the primary contact for a product.
- Go to MyAtlassian account. Sign in to your account or create a new one, it's super quick.
- Once you signed in, click Email preferences in the menu at the very top of the page.
- In Email preferences, scroll down to Alerts.
- Select products for which you would like to receive alerts about security advisories, maintenance notifications, and pricing updates.
- Select the format in which we'll send you the emails. You can choose between HTML and text.
- Click Update my email preferences to save the new configuration.
Security advisories
- Multiple Products Security Advisory - Unrendered unicode bidirectional override characters - CVE-2021-42574 - 2021-11-01
- Bamboo Security Advisory 2021-04-07
- Bamboo Security Advisory 2018-03-28
- Bamboo Security Advisory 2017-12-13
- Bamboo Security Advisory 2017-10-11
- Bamboo Security Advisory 2017-06-14
- Bamboo Security Advisory 2017-03-10
- Bamboo Security Advisory 2016-07-20
- Bamboo Security Advisory 2016-01-20
- Bamboo Security Advisory 2015-10-21
- Bamboo Security Advisory 2015-06-17
- Bamboo Security Advisory 2015-01-21
- Bamboo Security Advisory 2014-05-21
- Bamboo Security Advisory 2014-02-26
- Bamboo Security Advisory 2013-07-16
- Bamboo Security Advisory 2012-08-28
- Bamboo Security Advisory 2012-05-17
- Bamboo Security Advisory 2012-01-31
- Bamboo Security Advisory 2011-11-22
- Bamboo Security Advisory 2011-03-29
- Bamboo Security Advisory 2010-05-04
- Bamboo Security Advisory 2009-03-09
- Bamboo Security Advisory 2008-02-08 (Bamboo 2.0 Beta)