VulnerabilityModified
CVE-2016-5229
Atlassian Bamboo before 5.11.4.1 and 5.12.x before 5.12.3.1 does not properly restrict permitted deserialized classes, which allows remote attackers to execute arbitrary code via vectors related to XStream Serialization.
CRITICAL 9.8EPSS 7.09%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (7.09%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Atlassian Bamboo before 5.11.4.1 and 5.12.x before 5.12.3.1 does not properly restrict permitted deserialized classes, which allows remote attackers to execute arbitrary code via vectors related to XStream Serialization.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 7.09% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- atlassian/bamboo
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/138053/Bamboo-Deserialization-Issue.htmlThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/539003/100/0/threaded
- http://www.securityfocus.com/bid/92057Third Party Advisory, VDB Entry
- https://confluence.atlassian.com/bamboo/bamboo-security-advisory-2016-07-20-831660461.htmlVendor Advisory
- https://jira.atlassian.com/browse/BAM-17736Issue Tracking
- http://packetstormsecurity.com/files/138053/Bamboo-Deserialization-Issue.htmlThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/539003/100/0/threaded
- http://www.securityfocus.com/bid/92057Third Party Advisory, VDB Entry
- https://confluence.atlassian.com/bamboo/bamboo-security-advisory-2016-07-20-831660461.htmlVendor Advisory
- https://jira.atlassian.com/browse/BAM-17736Issue Tracking
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.