Описание
Atlassian Bamboo before 5.11.4.1 and 5.12.x before 5.12.3.1 does not properly restrict permitted deserialized classes, which allows remote attackers to execute arbitrary code via vectors related to XStream Serialization.
Ссылки
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Vendor Advisory
- Issue Tracking
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Vendor Advisory
- Issue Tracking
Уязвимые конфигурации
Конфигурация 1Версия до 5.11.3 (включая)
Одно из
cpe:2.3:a:atlassian:bamboo:*:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:bamboo:5.12.0:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:bamboo:5.12.1:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:bamboo:5.12.2:*:*:*:*:*:*:*
EPSS
Процентиль: 90%
0.0603
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-284
Связанные уязвимости
CVSS3: 9.8
github
больше 3 лет назад
Atlassian Bamboo before 5.11.4.1 and 5.12.x before 5.12.3.1 does not properly restrict permitted deserialized classes, which allows remote attackers to execute arbitrary code via vectors related to XStream Serialization.
EPSS
Процентиль: 90%
0.0603
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-284