-
Bug
-
Resolution: Fixed
-
Low
-
None
-
None
-
Severity 3 - Minor
-
The Github repository importer in Atlassian Bitbucket Server before version 5.3.0 allows remote attackers to determine if a service they could not otherwise reach has open ports via a Server Side Request Forgery (SSRF) vulnerability.
This is an independent assessment and you should evaluate its applicability to your own IT environment.
CVSS v3 score: 3.5 => Low severity
Exploitability Metrics
Scope Metric
Impact Metrics