PT-2017-18026 · Atlassian+1 · Bamboo Data Center/Server+2

Published

2017-04-29

·

Updated

2024-06-15

·

CVE-2017-7957

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions XStream versions 1.4.9 and earlier Bamboo Data Center and Server version 9.2.1
Description The issue concerns XStream, where attempts to create an instance of the primitive type void during unmarshalling can lead to a remote application crash. This can be demonstrated by an xstream.fromXML("<void/>") call. The vulnerability allows an unauthenticated attacker to expose assets in the environment, susceptible to exploitation, with no impact to confidentiality, no impact to integrity, and high impact to availability, requiring no user interaction.
Recommendations For XStream versions 1.4.9 and earlier, upgrade to a version greater than 1.4.9. For Bamboo Data Center and Server version 9.2.1, upgrade to a release greater than or equal to 9.2.8.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-7957
DLA-930-1
DSA-3841-1
GHSA-7HWC-46RM-65JH
OPENSUSE-SU-2024:10592-1
SUSE-RU-2019:1006-1
SUSE-SU-2017:3389-1
SUSE-SU-2017:3390-1
SUSE-SU-2019:1006-1

Affected Products

Bamboo
Bamboo Data Center/Server
Xstream