- 
    Bug 
- 
    Resolution: Fixed
- 
    Medium 
- 
    None
- 
    None
- 
        Severity 2 - Major
- 
        
The repository settings resource in Atlassian Bitbucket Server before version 5.6.0 allows remote attackers to read the first line of arbitrary files via a path traversal vulnerability through the default branch name.