YAML File Parsing Flaw in Atlassian Bamboo Products
CVE-2017-9514
8.8HIGH
Summary
A vulnerability in Atlassian Bamboo's YAML file parsing mechanism allows authenticated users to exploit a REST endpoint that does not adequately restrict the classes that can be loaded. This potential misconfiguration can be leveraged by an attacker with valid user credentials to execute arbitrary Java code on vulnerable systems, posing a severe risk to the integrity and security of the affected installations. The flaw is found in Bamboo versions prior to 6.0.5, 6.1.x versions earlier than 6.1.4, and 6.2.x versions before 6.2.1.
Affected Version(s)
Bamboo from 6.0.0 before 6.0.5
Bamboo from 6.1.0 before 6.1.4
Bamboo from 6.2.0 before 6.2.1
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved