Affected versions of Atlassian Bitbucket Data Center allow remote attackers to access the content of internal network resources via a Server-Side Request Forgery (SSRF) vulnerability in Webhooks.

      When running in an environment like Amazon EC2, this flaw may be used to access to a metadata resource that provides access credentials and other potentially confidential information.

            [BSERV-12433] SSRF in Webhooks - CVE-2020-14170

            No work has yet been logged on this issue.

              8ab5f4fb2885 Dyon Georgopoulos
              security-metrics-bot Security Metrics Bot
              Affected customers:
              1 This affects my team
              Watchers:
              8 Start watching this issue

                Created:
                Updated:
                Resolved: