CVE Database
/

CVE-2017-18037

Back to search

CVE-2017-18037

Published: Feb 2, 2018

Modified: Sep 16, 2024

PUBLISHED

Description

The git repository tag rest resource in Atlassian Bitbucket Server from version 3.7.0 before 4.14.11 (the fixed version for 4.14.x), from version 5.0.0 before 5.0.9 (the fixed version for 5.0.x), from version 5.1.0 before 5.1.8 (the fixed version for 5.1.x), from version 5.2.0 before 5.2.6 (the fixed version for 5.2.x), from version 5.3.0 before 5.3.4 (the fixed version for 5.3.x), from version 5.4.0 before 5.4.2 (the fixed version for 5.4.x), from version 5.5.0 before 5.5.1 (the fixed version for 5.5.x) and before 5.6.0 allows remote attackers to read arbitrary files via a path traversal vulnerability through the name of a git tag.

VendorProductVersions

Atlassian

Bitbucket Server

affected
from 3.7.0 prior to 4.14.11
affected
from 5.0.0 prior to 5.0.9
affected
from 5.1.0 prior to 5.1.8
affected
from 5.2.0 prior to 5.2.6
affected
from 5.3.0 prior to 5.3.4

+2 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now