CVE-2016-5229
02.08.2016, 16:59
Atlassian Bamboo before 5.11.4.1 and 5.12.x before 5.12.3.1 does not properly restrict permitted deserialized classes, which allows remote attackers to execute arbitrary code via vectors related to XStream Serialization.Enginsight
Vendor | Product | Version |
---|---|---|
atlassian | bamboo | 𝑥 ≤ 5.11.3 |
atlassian | bamboo | 5.12.0 |
atlassian | bamboo | 5.12.1 |
atlassian | bamboo | 5.12.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References