CVE-2017-18037
Summary
| CVE | CVE-2017-18037 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-02-02 14:29:00 UTC |
| Updated | 2018-02-24 16:26:00 UTC |
| Description | The git repository tag rest resource in Atlassian Bitbucket Server from version 3.7.0 before 4.14.11 (the fixed version for 4.14.x), from version 5.0.0 before 5.0.9 (the fixed version for 5.0.x), from version 5.1.0 before 5.1.8 (the fixed version for 5.1.x), from version 5.2.0 before 5.2.6 (the fixed version for 5.2.x), from version 5.3.0 before 5.3.4 (the fixed version for 5.3.x), from version 5.4.0 before 5.4.2 (the fixed version for 5.4.x), from version 5.5.0 before 5.5.1 (the fixed version for 5.5.x) and before 5.6.0 allows remote attackers to read arbitrary files via a path traversal vulnerability through the name of a git tag. |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Atlassian | Bitbucket | All | All | All | All |
| Application | Atlassian | Bitbucket | 5.5.0 | All | All | All |
| Application | Atlassian | Bitbucket | 5.5.2 | All | All | All |
| Application | Atlassian | Bitbucket | 5.5.3 | All | All | All |
| Application | Atlassian | Bitbucket | 5.5.4 | All | All | All |
| Application | Atlassian | Bitbucket | 5.5.5 | All | All | All |
| Application | Atlassian | Bitbucket | 5.5.6 | All | All | All |
| Application | Atlassian | Bitbucket | All | All | All | All |
| Application | Atlassian | Bitbucket | 5.5.0 | All | All | All |
| Application | Atlassian | Bitbucket | 5.5.2 | All | All | All |
| Application | Atlassian | Bitbucket | 5.5.3 | All | All | All |
| Application | Atlassian | Bitbucket | 5.5.4 | All | All | All |
| Application | Atlassian | Bitbucket | 5.5.5 | All | All | All |
| Application | Atlassian | Bitbucket | 5.5.6 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [BSERV-10595] Path traversal through the name of a git tag in the git repository tag rest resource - CVE-2017-18037 - Create and track feature requests for Atlassian products. | CONFIRM | jira.atlassian.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.