Lucene search

K
atlassianSecurity-metrics-botATLASSIAN:BSERV-10595
HistoryFeb 02, 2018 - 12:12 a.m.

Path traversal through the name of a git tag in the git repository tag rest resource - CVE-2017-18037

2018-02-0200:12:12
security-metrics-bot
jira.atlassian.com
92

0.002 Low

EPSS

Percentile

55.4%

The git repository tag rest resource in Atlassian Bitbucket Server from version 3.7.0 before 4.14.11 (the fixed version for 4.14.x), from version 5.0.0 before 5.0.9 (the fixed version for 5.0.x), from version 5.1.0 before 5.1.8 (the fixed version for 5.1.x), from version 5.2.0 before 5.2.6 (the fixed version for 5.2.x), from version 5.3.0 before 5.3.4 (the fixed version for 5.3.x), from version 5.4.0 before 5.4.2 (the fixed version for 5.4.x), from version 5.5.0 before 5.5.1 (the fixed version for 5.5.x) and before 5.6.0 allows remote attackers to read arbitrary files via a path traversal vulnerability through the name of a git tag.

0.002 Low

EPSS

Percentile

55.4%

Related for ATLASSIAN:BSERV-10595