CVE-2017-18038

CWE-22Path Traversal3 documents3 sources
Severity
5.3MEDIUM
EPSS
0.2%
top 54.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 2
Latest updateMay 14

Description

The repository settings resource in Atlassian Bitbucket Server before version 5.6.0 allows remote attackers to read the first line of arbitrary files via a path traversal vulnerability through the default branch name.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

CVEListV5atlassian/bitbucket_serverprior to 5.6.0
NVDatlassian/bitbucket< 5.6.0

🔴Vulnerability Details

2
GHSA
GHSA-w5r2-hxmg-8w48: The repository settings resource in Atlassian Bitbucket Server before version 52022-05-14
CVEList
CVE-2017-18038: The repository settings resource in Atlassian Bitbucket Server before version 52018-02-02