First published: Tue Aug 02 2016(Updated: )
Atlassian Bamboo before 5.11.4.1 and 5.12.x before 5.12.3.1 does not properly restrict permitted deserialized classes, which allows remote attackers to execute arbitrary code via vectors related to XStream Serialization.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bamboo | <=5.11.3 | |
Bamboo | =5.12.0 | |
Bamboo | =5.12.1 | |
Bamboo | =5.12.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5229 has a high severity rating due to its potential for remote code execution.
To fix CVE-2016-5229, upgrade Atlassian Bamboo to version 5.11.4.1 or 5.12.3.1 or later.
CVE-2016-5229 affects Atlassian Bamboo versions up to and including 5.11.3 and specific 5.12.x versions before 5.12.3.1.
CVE-2016-5229 is a deserialization vulnerability that allows for arbitrary code execution.
Yes, CVE-2016-5229 can be exploited remotely by an attacker to execute arbitrary code.