Unrated severityNVD Advisory· Published Feb 15, 2018· Updated Sep 17, 2024
CVE-2017-18087
CVE-2017-18087
Description
The download commit resource in Atlassian Bitbucket Server from version 5.1.0 before version 5.1.7, from version 5.2.0 before version 5.2.5, from version 5.3.0 before version 5.3.3 and from version 5.4.0 before version 5.4.1 allows remote attackers to write files to disk potentially allowing them to gain code execution, exploit CVE-2017-1000117 if a vulnerable version of git is in use, and or determine if an internal service exists via an argument injection vulnerability in the at parameter.
Affected products
1- Range: from 5.1.0 prior to 5.1.7
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.securityfocus.com/bid/103038mitrevdb-entryx_refsource_BID
- jira.atlassian.com/browse/BSERV-10593mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.