Uploaded image for project: 'Bitbucket Data Center'
  1. Bitbucket Data Center
  2. BSERV-10593

Argument injection in the download commit resource through the at parameter - CVE-2017-18087

      The download commit resource in Atlassian Bitbucket Server from version 5.1.0 before version 5.1.7, from version 5.2.0 before version 5.2.5, from version 5.3.0 before version 5.3.3 and from version 5.4.0 before version 5.4.1 allows remote attackers to write files to disk potentially allowing them to gain code execution, exploit CVE-2017-1000117 if a vulnerable version of git is in use, and or determine if an internal service exists via an argument injection vulnerability in the at parameter.

          Form Name

            [BSERV-10593] Argument injection in the download commit resource through the at parameter - CVE-2017-18087

            Richard Atkins made changes -
            Labels Original: CVE-2017-18087 advisory advisory-released bugbounty command-injection cvss-high security New: CVE-2017-18087 advisory advisory-released bugbounty command-injection cvss-high injection security
            Owen made changes -
            Workflow Original: Stash Workflow - Restricted [ 2594774 ] New: JAC Bug Workflow v3 [ 3137278 ]
            Owen made changes -
            Symptom Severity Original: Critical [ 14430 ] New: Severity 1 - Critical [ 15830 ]
            Lucy made changes -
            Remote Link New: This issue links to "Page (Extranet)" [ 357235 ]
            David Black made changes -
            Labels Original: CVE-2017-18087 advisory advisory-to-release bugbounty command-injection cvss-high security New: CVE-2017-18087 advisory advisory-released bugbounty command-injection cvss-high security
            David Black made changes -
            Security Original: Atlassian Staff [ 10750 ]
            David Black made changes -
            Labels Original: advisory advisory-to-release bugbounty command-injection cvss-high security New: CVE-2017-18087 advisory advisory-to-release bugbounty command-injection cvss-high security
            David Black made changes -
            Summary Original: Argument injection in the download commit resource - CVE-2017-18087 New: Argument injection in the download commit resource through the at parameter - CVE-2017-18087
            David Black made changes -
            Description Original: The download commit resource in Atlassian Bitbucket Server from version 5.1.0 before version 5.1.7, from version 5.2.0 before version 5.2.5, from version 5.3.0 before version 5.3.3 and from version 5.4.0 before version 5.4.1 allows remote attackers to write files to disk potentially allowing them to gain code execution, exploit CVE-2017-1000117 if a vulnerable version of git is in use, and or determine if an internal service exists via an argument injection vulnerability. New: The download commit resource in Atlassian Bitbucket Server from version 5.1.0 before version 5.1.7, from version 5.2.0 before version 5.2.5, from version 5.3.0 before version 5.3.3 and from version 5.4.0 before version 5.4.1 allows remote attackers to write files to disk potentially allowing them to gain code execution, exploit CVE-2017-1000117 if a vulnerable version of git is in use, and or determine if an internal service exists via an argument injection vulnerability in the at parameter.
            David Black made changes -
            Description Original: The download commit resource in Atlassian Bitbucket Server from version 5.1.0 before version 5.1.7, from version 5.2.0 before version 5.2.5, from version 5.3.0 before version 5.3.3, and from version 5.4.0 before version 5.4.1 allows remote attackers to write files to disk potentially allowing them to gain code execution, exploit CVE-2017-1000117 if a vulnerable version of git is in use, and or determine if an internal service exists via an argument injection vulnerability. New: The download commit resource in Atlassian Bitbucket Server from version 5.1.0 before version 5.1.7, from version 5.2.0 before version 5.2.5, from version 5.3.0 before version 5.3.3 and from version 5.4.0 before version 5.4.1 allows remote attackers to write files to disk potentially allowing them to gain code execution, exploit CVE-2017-1000117 if a vulnerable version of git is in use, and or determine if an internal service exists via an argument injection vulnerability.

              Unassigned Unassigned
              security-metrics-bot Security Metrics Bot
              Affected customers:
              0 This affects my team
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: