CVE-2018-5225
Last modified
CVE-2018-5225 is a vulnerability of currently unknown severity. In browser editing in Atlassian Bitbucket Server from version 4.13.0 before 5.4.8 (the fixed version for 4.13.0 through 5.4.7), 5.5.0 before 5.5.8 (the fixed version for 5.5.x), 5.6.0 before 5.6.5 (the fixed version for 5.6.x), 5.7.0 before 5.7.3 (the fixed version for 5.7.x), and 5.8.0 before 5.8.2 (the fixed version for 5.8.x), allows authenticated users to gain remote code execution using the in browser editing feature via editing a symbolic link within a repository.. EPSS estimates a 3.62% chance of exploitation in the next 30 days.
Description
In browser editing in Atlassian Bitbucket Server from version 4.13.0 before 5.4.8 (the fixed version for 4.13.0 through 5.4.7), 5.5.0 before 5.5.8 (the fixed version for 5.5.x), 5.6.0 before 5.6.5 (the fixed version for 5.6.x), 5.7.0 before 5.7.3 (the fixed version for 5.7.x), and 5.8.0 before 5.8.2 (the fixed version for 5.8.x), allows authenticated users to gain remote code execution using the in browser editing feature via editing a symbolic link within a repository.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Atlassian | Bitbucket | >= 4.13.0, < 5.4.8 |
| Atlassian | Bitbucket | > 5.5.0, < 5.5.8 |
| Atlassian | Bitbucket | >= 5.6.0, < 5.6.5 |
| Atlassian | Bitbucket | >= 5.7.0, < 5.7.3 |
| Atlassian | Bitbucket | >= 5.8.0, < 5.8.2 |
References
- http://www.securityfocus.com/bid/103488Third Party Advisory, VDB Entry
- https://confluence.atlassian.com/x/3WNsOVendor Advisory
- https://jira.atlassian.com/browse/BSERV-10684Vendor Advisory
- http://www.securityfocus.com/bid/103488Third Party Advisory, VDB Entry
- https://confluence.atlassian.com/x/3WNsOVendor Advisory
- https://jira.atlassian.com/browse/BSERV-10684Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-5225?
How severe is CVE-2018-5225?
How do I fix CVE-2018-5225?
Are you affected by CVE-2018-5225?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
