First published: Tue Aug 02 2016(Updated: )
Atlassian Bamboo before 5.11.4.1 and 5.12.x before 5.12.3.1 does not properly restrict permitted deserialized classes, which allows remote attackers to execute arbitrary code via vectors related to XStream Serialization.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Bamboo | <=5.11.3 | |
Atlassian Bamboo | =5.12.0 | |
Atlassian Bamboo | =5.12.1 | |
Atlassian Bamboo | =5.12.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.