YAML File Parsing Flaw in Atlassian Bamboo Products
CVE-2017-9514
8.8HIGH
What is CVE-2017-9514?
A vulnerability in Atlassian Bamboo's YAML file parsing mechanism allows authenticated users to exploit a REST endpoint that does not adequately restrict the classes that can be loaded. This potential misconfiguration can be leveraged by an attacker with valid user credentials to execute arbitrary Java code on vulnerable systems, posing a severe risk to the integrity and security of the affected installations. The flaw is found in Bamboo versions prior to 6.0.5, 6.1.x versions earlier than 6.1.4, and 6.2.x versions before 6.2.1.
Affected Version(s)
Bamboo from 6.0.0 before 6.0.5
Bamboo from 6.1.0 before 6.1.4
Bamboo from 6.2.0 before 6.2.1