CVE-2016-5229: Atlassian Bamboo

Critical severity, CVSS 9.8. EPSS: 7.1% chance of exploitation in the next 30 days.

Atlassian Bamboo before 5.11.4.1 and 5.12.x before 5.12.3.1 does not properly restrict permitted deserialized classes, which allows remote attackers to execute arbitrary code via vectors related to XStream Serialization.

Affected products

  • Atlassian Bamboo: up to and including 5.11.3; version 5.12.0 only; version 5.12.1 only; version 5.12.2 only

Published 2016-08-02. Last modified 2026-06-17.