An authenticated user of Bitbucket Server could gain remote code execution using the in browser editing feature via editing a symbolic link within a repository.
Affected versions:
- All versions of Bitbucket Server before 5.4.8 (the fixed version for 4.13.0 through to 5.4.7), 5.5.0 before 5.5.8 (the fixed version for 5.5.x), 5.6.0 before 5.6.5 (the fixed version for 5.6.x), 5.7.0 before 5.7.3 (the fixed version for 5.7.x), and 5.8.0 before 5.8.2 (the fixed version for 5.8.x) are affected by this vulnerability. Bitbucket Server 5.9.0 is not impacted by this vulnerability
Fix:
- Bitbucket Server version 5.9.0 is available to download from https://www.atlassian.com/software/bitbucket/download.
- Bitbucket Server version 5.8.2 is available to download from https://www.atlassian.com/software/bitbucket/download-archives.
- Bitbucket Server version 5.7.3 is available to download from https://www.atlassian.com/software/bitbucket/download-archives.
- Bitbucket Server version 5.6.5 is available to download from https://www.atlassian.com/software/bitbucket/download-archives.
- Bitbucket Server version 5.5.8 is available to download from https://www.atlassian.com/software/bitbucket/download-archives.
- Bitbucket Server version 5.4.8 is available to download from https://www.atlassian.com/software/bitbucket/download-archives.
For additional details see the full advisory.
- relates to
-
SECENG-1329 Loading...