CVE-2017-18037 is a vulnerability in Atlassian Bitbucket
Published on February 2, 2018
The git repository tag rest resource in Atlassian Bitbucket Server from version 3.7.0 before 4.14.11 (the fixed version for 4.14.x), from version 5.0.0 before 5.0.9 (the fixed version for 5.0.x), from version 5.1.0 before 5.1.8 (the fixed version for 5.1.x), from version 5.2.0 before 5.2.6 (the fixed version for 5.2.x), from version 5.3.0 before 5.3.4 (the fixed version for 5.3.x), from version 5.4.0 before 5.4.2 (the fixed version for 5.4.x), from version 5.5.0 before 5.5.1 (the fixed version for 5.5.x) and before 5.6.0 allows remote attackers to read arbitrary files via a path traversal vulnerability through the name of a git tag.
Products Associated with CVE-2017-18037
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2017-18037 are published in Atlassian Bitbucket:
Affected Versions
Atlassian Bitbucket Server:- Version from 3.7.0 prior to 4.14.11 is affected.
- Version from 5.0.0 prior to 5.0.9 is affected.
- Version from 5.1.0 prior to 5.1.8 is affected.
- Version from 5.2.0 prior to 5.2.6 is affected.
- Version from 5.3.0 prior to 5.3.4 is affected.
- Version from 5.4.0 prior to 5.4.2 is affected.
- Version from 5.5.0 prior to 5.5.1 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.