CVE漏洞中文网

0DayBank一个专门收集整理全球互联网漏洞的公开发布网站
  1. 首页
  2. CVE
  3. 正文

CVE-2015-6576 Atlassian Bamboo Java Deserialization Code Execution Vulnerability.

2017年1月9日 1063点热度 0人点赞 0条评论

漏洞类别:CGI

漏洞等级:

漏洞信息

Bamboo is a continuous integration and deployment tool that ties automated builds, tests and releases together in a single workflow.

Bamboo had a resource that deserialised arbitrary user input without restriction. Attackers can use this vulnerability to execute Java code of their choice on systems that have a vulnerable version of Bamboo.

Affected Versions
Version prior to 5.8.5 from 2.2 And version prior to 5.9.7 from 5.9.0

漏洞危害

Attackers can use this vulnerability to execute Java code of their choice on systems that have a vulnerable version of Bamboo.

解决方案

Vendor has released fix to address this vulnerability. Download it from here.

Patch:
Following are links for downloading patches to fix the vulnerabilities:

BAM-16439

0day

标签: 暂无
最后更新:2017年1月9日

小助手

这个人很懒,什么都没留下

点赞
< 上一篇
下一篇 >

文章评论

您需要 登录 之后才可以评论

COPYRIGHT © 2024 www.pdr.cn CVE漏洞中文网. ALL RIGHTS RESERVED.

鲁ICP备2022031030号

联系邮箱:wpbgssyubnmsxxxkkk@proton.me