Lucene search

K
atlassianSmoorthyATLASSIAN:BAM-20722
HistoryNov 19, 2019 - 8:26 p.m.

RCE jackson-databind

2019-11-1920:26:41
smoorthy
jira.atlassian.com
124

0.012 Low

EPSS

Percentile

85.1%

h3. Issue Summary
https://hello.atlassian.net/wiki/spaces/SECURITY/pages/566213966/CVE-2019-17267+Investigation+jackson-databind+RCE+again

h3. Steps to Reproduce

search on stash for jackson-databind

https://stash.atlassian.com/plugins/servlet/search?q=project%3ABAM repo%3Abamboo jackson-databind

h3. Expected Results

version 2.10.0 or above

h3. Actual Results

are there vulnerable versions in this repo or others that belong to Bamboo?
The below exception is thrown in the xxxxxxx.log file:
{noformat}
…
{noformat}

h3. Workaround
Currently there is no known workaround for this

CPENameOperatorVersion
bamboole6.10.2