Atlassian Bamboo before 5.11.4.1 and 5.12.x before 5.12.3.1 does not properly restrict permitted deserialized classes, which allows remote attackers to execute arbitrary code via vectors related to XStream Serialization.
| Software | From | Fixed in |
|---|---|---|
| atlassian / bamboo | 5.12.0 | 5.12.0.x |
| atlassian / bamboo | 5.12.2 | 5.12.2.x |
| atlassian / bamboo | - | 5.11.3.x |
| atlassian / bamboo | 5.12.1 | 5.12.1.x |