PT-2018-6666 · Atlassian · Bitbucket Server+1

Published

2018-02-15

·

Updated

2019-10-03

·

CVE-2017-18087

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Atlassian Bitbucket Server versions 5.1.0 through 5.1.7 Atlassian Bitbucket Server versions 5.2.0 through 5.2.5 Atlassian Bitbucket Server versions 5.3.0 through 5.3.3 Atlassian Bitbucket Server versions 5.4.0 through 5.4.1
Description: The issue allows remote attackers to write files to disk, potentially leading to code execution. It can also be exploited to determine if an internal service exists via an argument injection vulnerability in the at parameter.
Recommendations: For versions 5.1.0 through 5.1.7, update to version 5.1.7 or later. For versions 5.2.0 through 5.2.5, update to version 5.2.5 or later. For versions 5.3.0 through 5.3.3, update to version 5.3.3 or later. For versions 5.4.0 through 5.4.1, update to version 5.4.1 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2017-18087

Affected Products

Bitbucket Server
Bitbucket