CVE-2016-5229: Critical severity bamboo vulnerability
Published Aug 2, 2016
·Updated
Atlassian Bamboo before 5.11.4.1 and 5.12.x before 5.12.3.1 does not properly restrict permitted deserialized classes, which allows remote attackers to execute arbitrary code via vectors related to XStream Serialization.
Affected Software
4 affected components
Atlassian Bamboo<=5.11.3
Atlassian Bamboo=5.12.0
Atlassian Bamboo=5.12.1
Atlassian Bamboo=5.12.2
Event History
Aug 2, 2016
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-5229?
CVE-2016-5229 has a high severity rating due to its potential for remote code execution.
2
How do I fix CVE-2016-5229?
To fix CVE-2016-5229, upgrade Atlassian Bamboo to version 5.11.4.1 or 5.12.3.1 or later.
3
What systems are affected by CVE-2016-5229?
CVE-2016-5229 affects Atlassian Bamboo versions up to and including 5.11.3 and specific 5.12.x versions before 5.12.3.1.
4
What type of vulnerability is CVE-2016-5229?
CVE-2016-5229 is a deserialization vulnerability that allows for arbitrary code execution.
5
Can CVE-2016-5229 be exploited remotely?
Yes, CVE-2016-5229 can be exploited remotely by an attacker to execute arbitrary code.