CVE-2017-18088
published 2018-02-15CVE-2017-18088: Various plugin servlet resources in Atlassian Bitbucket Server before version 5.3.7 (the fixed version for 5.3.x), from version 5.4.0 before 5.4.6 (the fixed…
PriorityP419medium4.3CVSS 3.0
AVNACLPRNUIRSUCNILAN
EPSS
1.01%
59.1th percentile
Various plugin servlet resources in Atlassian Bitbucket Server before version 5.3.7 (the fixed version for 5.3.x), from version 5.4.0 before 5.4.6 (the fixed version for 5.4.x), from version 5.5.0 before 5.5.6 (the fixed version for 5.5.x), from version 5.6.0 before 5.6.3 (the fixed version for 5.6.x), from version 5.7.0 before 5.7.1 (the fixed version for 5.7.x) and before 5.8.0 allow remote attackers to conduct clickjacking attacks via framing various resources that lacked clickjacking protection.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| atlassian | bitbucket | >= 5.3.0 < 5.3.7 | 5.3.7 |
| atlassian | bitbucket | >= 5.4.0 < 5.4.6 | 5.4.6 |
| atlassian | bitbucket | >= 5.5.0 < 5.5.6 | 5.5.6 |
| atlassian | bitbucket | >= 5.6.0 < 5.6.3 | 5.6.3 |
| atlassian | bitbucket | >= 5.7.0 < 5.7.1 | 5.7.1 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.3.0-2build0.18.04.1 | 2.3.0-2build0.18.04.1 |
CVSS provenance
nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g674-wrw3-m4q6: Various plugin servlet resources in Atlassian Bitbucket Server before version 5
ghsa_unreviewed·2022-05-14
CVE-2017-18088 [MEDIUM] CWE-20 GHSA-g674-wrw3-m4q6: Various plugin servlet resources in Atlassian Bitbucket Server before version 5
Various plugin servlet resources in Atlassian Bitbucket Server before version 5.3.7 (the fixed version for 5.3.x), from version 5.4.0 before 5.4.6 (the fixed version for 5.4.x), from version 5.5.0 before 5.5.6 (the fixed version for 5.5.x), from version 5.6.0 before 5.6.3 (the fixed version for 5.6.x), from version 5.7.0 before 5.7.1 (the fixed version for 5.7.x) and before 5.8.0 allow remote attackers to conduct clickjacking attacks via framing various resources that lacked clickjacking protection.
OSV
openjpeg2 vulnerabilities
osv·2019-08-21·CVSS 9.8
CVE-2017-17480 openjpeg2 vulnerabilities
openjpeg2 vulnerabilities
It was discovered that OpenJPEG incorrectly handled certain PGX files. An
attacker could possibly use this issue to cause a denial of service or possibly
remote code execution. (CVE-2017-17480)
It was discovered that OpenJPEG incorrectly handled certain files. An attacker
could possibly use this issue to cause a denial of service. (CVE-2018-14423)
It was discovered that OpenJPEG incorrectly handled certain PNM files. An
attacker could possibly use this issue to cause a denial of service.
(CVE-2018-18088)
It was discovered that OpenJPEG incorrectly handled certain BMP files. An
attacker could possibly use this issue to cause a denial of service.
(CVE-2018-5785, CVE-2018-6616)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-02-15
Published