CVE-2016-5229
Bamboo Deserialization Issue
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Atlassian Bamboo before 5.11.4.1 and 5.12.x before 5.12.3.1 does not properly restrict permitted deserialized classes, which allows remote attackers to execute arbitrary code via vectors related to XStream Serialization.
Atlassian Bamboo en versiones anteriores a 5.11.4.1 y 5.12.x en versiones anteriores a 5.12.3.1 no restringe adecuadamente clases deserializadas permitidas, lo que permite a atacantes remotos ejecutar código arbitrario a través de vectores relacionados con XStream Serialization.
This advisory discloses a critical severity security vulnerability which was introduced in version 2.3.1 of Bamboo. Versions of Bamboo starting with 2.3.1 before 5.11.4.1 (the fixed version for 5.11.x) and from 5.12.0 before 5.12.3.1 (the fixed version for 5.12.x) are affected by this vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-06-01 CVE Reserved
- 2016-07-26 CVE Published
- 2024-08-06 CVE Updated
- 2025-04-05 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-284: Improper Access Control
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.com/files/138053/Bamboo-Deserialization-Issue.html | Third Party Advisory |
|
http://www.securityfocus.com/archive/1/539003/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/92057 | Third Party Advisory | |
https://jira.atlassian.com/browse/BAM-17736 | Issue Tracking |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://confluence.atlassian.com/bamboo/bamboo-security-advisory-2016-07-20-831660461.html | 2018-10-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Atlassian Search vendor "Atlassian" | Bamboo Search vendor "Atlassian" for product "Bamboo" | <= 5.11.3 Search vendor "Atlassian" for product "Bamboo" and version " <= 5.11.3" | - |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Bamboo Search vendor "Atlassian" for product "Bamboo" | 5.12.0 Search vendor "Atlassian" for product "Bamboo" and version "5.12.0" | - |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Bamboo Search vendor "Atlassian" for product "Bamboo" | 5.12.1 Search vendor "Atlassian" for product "Bamboo" and version "5.12.1" | - |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Bamboo Search vendor "Atlassian" for product "Bamboo" | 5.12.2 Search vendor "Atlassian" for product "Bamboo" and version "5.12.2" | - |
Affected
|