CVE-2017-18087
Published: Feb 15, 2018
Modified: Sep 17, 2024
Description
The download commit resource in Atlassian Bitbucket Server from version 5.1.0 before version 5.1.7, from version 5.2.0 before version 5.2.5, from version 5.3.0 before version 5.3.3 and from version 5.4.0 before version 5.4.1 allows remote attackers to write files to disk potentially allowing them to gain code execution, exploit CVE-2017-1000117 if a vulnerable version of git is in use, and or determine if an internal service exists via an argument injection vulnerability in the at parameter.
| Vendor | Product | Versions |
|---|---|---|
Atlassian | Bitbucket Server | affected from 5.1.0 prior to 5.1.7affected from 5.2.0 prior to 5.2.5affected from 5.3.0 prior to 5.3.3affected from 5.4.0 prior to 5.4.1 |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now