CVE-2017-16857

UnknownEPSS 0.59%

Last modified

CVE-2017-16857 is a vulnerability of currently unknown severity. It is possible to bypass the bitbucket auto-unapprove plugin via minimal brute-force because it is relying on asynchronous events on the back-end. This allows an attacker to merge any code into unsuspecting repositories. EPSS estimates a 0.59% chance of exploitation in the next 30 days.

Description

It is possible to bypass the bitbucket auto-unapprove plugin via minimal brute-force because it is relying on asynchronous events on the back-end. This allows an attacker to merge any code into unsuspecting repositories. This affects all versions of the auto-unapprove plugin, however since the auto-unapprove plugin is not bundled with Bitbucket Server it does not affect any particular version of Bitbucket.

Metrics

EPSS Probability
0.59%

43.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
AtlassianBitbucket Auto Unapprove Plugin1.0.0
AtlassianBitbucket Auto Unapprove Plugin1.1.0
AtlassianBitbucket Auto Unapprove Plugin1.2.0
AtlassianBitbucket Auto Unapprove Plugin2.0.1
AtlassianBitbucket Auto Unapprove Plugin2.0.2
AtlassianBitbucket Auto Unapprove Plugin2.0.4
AtlassianBitbucket Auto Unapprove Plugin2.1.1
AtlassianBitbucket Auto Unapprove Plugin2.1.3
AtlassianBitbucket Auto Unapprove Plugin2.2.0
AtlassianBitbucket Auto Unapprove Plugin3.0.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2017-16857?
It is possible to bypass the bitbucket auto-unapprove plugin via minimal brute-force because it is relying on asynchronous events on the back-end. This allows an attacker to merge any code into unsuspecting repositories. This affects all versions of the auto-unapprove plugin, however since the auto-unapprove plugin is not bundled with Bitbucket Server it does not affect any particular version of Bitbucket.
How severe is CVE-2017-16857?
Severity scoring for CVE-2017-16857 is pending analysis. The EPSS model estimates a 0.59% probability of exploitation in the next 30 days.
How do I fix CVE-2017-16857?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2017-16857?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST