PT-2018-6666 · Atlassian · Bitbucket Server+1
Published
2018-02-15
·
Updated
2019-10-03
·
CVE-2017-18087
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Atlassian Bitbucket Server versions 5.1.0 through 5.1.7
Atlassian Bitbucket Server versions 5.2.0 through 5.2.5
Atlassian Bitbucket Server versions 5.3.0 through 5.3.3
Atlassian Bitbucket Server versions 5.4.0 through 5.4.1
Description:
The issue allows remote attackers to write files to disk, potentially leading to code execution. It can also be exploited to determine if an internal service exists via an argument injection vulnerability in the
at parameter.Recommendations:
For versions 5.1.0 through 5.1.7, update to version 5.1.7 or later.
For versions 5.2.0 through 5.2.5, update to version 5.2.5 or later.
For versions 5.3.0 through 5.3.3, update to version 5.3.3 or later.
For versions 5.4.0 through 5.4.1, update to version 5.4.1 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bitbucket Server
Bitbucket