CVE-2017-18087 Information

Description

The download commit resource in Atlassian Bitbucket Server from version 5.1.0 before version 5.1.7 from version 5.2.0 before version 5.2.5 from version 5.3.0 before version 5.3.3 and from version 5.4.0 before version 5.4.1 allows remote attackers to write files to disk potentially allowing them to gain code execution exploit CVE-2017-1000117 if a vulnerable version of git is in use and or determine if an internal service exists via an argument injection vulnerability in the at parameter.

CVSS Vector

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Reference

http://www.securityfocus.com/bid/103038 https://jira.atlassian.com/browse/BSERV-10593

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

7.5

Share on: