{"api_version":"1","generated_at":"2026-07-23T22:22:21+00:00","cve":"CVE-2018-5225","urls":{"html":"https://cve.report/CVE-2018-5225","api":"https://cve.report/api/cve/CVE-2018-5225.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-5225","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-5225"},"summary":{"title":"CVE-2018-5225","description":"In browser editing in Atlassian Bitbucket Server from version 4.13.0 before 5.4.8 (the fixed version for 4.13.0 through 5.4.7), 5.5.0 before 5.5.8 (the fixed version for 5.5.x), 5.6.0 before 5.6.5 (the fixed version for 5.6.x), 5.7.0 before 5.7.3 (the fixed version for 5.7.x), and 5.8.0 before 5.8.2 (the fixed version for 5.8.x), allows authenticated users to gain remote code execution using the in browser editing feature via editing a symbolic link within a repository.","state":"PUBLIC","assigner":"security@atlassian.com","published_at":"2018-03-22 13:29:00","updated_at":"2018-04-20 16:57:00"},"problem_types":["CWE-59"],"metrics":[],"references":[{"url":"https://jira.atlassian.com/browse/BSERV-10684","name":"https://jira.atlassian.com/browse/BSERV-10684","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"[BSERV-10684] Remote Code Execution via in Browser Editing - CVE-2018-5225 - Create and track feature requests for Atlassian products.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/103488","name":"103488","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"Atlassian Bitbucket Server CVE-2018-5225 Remote Code Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://confluence.atlassian.com/x/3WNsO","name":"https://confluence.atlassian.com/x/3WNsO","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Bitbucket Server security advisory 2018-03-21 | Bitbucket Data Center and Server 7.8 | Atlassian Documentation","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-5225","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-5225","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"5225","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"atlassian","cpe5":"bitbucket","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"5225","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"atlassian","cpe5":"bitbucket","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security@atlassian.com","DATE_PUBLIC":"2018-03-22T10:00:00","ID":"CVE-2018-5225","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Bitbucket Server","version":{"version_data":[{"version_affected":">=","version_value":"4.13.0"},{"version_affected":"<","version_value":"5.4.8"},{"version_affected":">=","version_value":"5.5.0"},{"version_affected":"<","version_value":"5.5.8"},{"version_affected":">=","version_value":"5.6.0"},{"version_affected":"<","version_value":"5.6.5"},{"version_affected":">=","version_value":"5.7.0"},{"version_affected":"<","version_value":"5.7.3"},{"version_affected":">=","version_value":"5.8.0"},{"version_affected":"<","version_value":"5.8.2"}]}}]},"vendor_name":"Atlassian"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"In browser editing in Atlassian Bitbucket Server from version 4.13.0 before 5.4.8 (the fixed version for 4.13.0 through 5.4.7), 5.5.0 before 5.5.8 (the fixed version for 5.5.x), 5.6.0 before 5.6.5 (the fixed version for 5.6.x), 5.7.0 before 5.7.3 (the fixed version for 5.7.x), and 5.8.0 before 5.8.2 (the fixed version for 5.8.x), allows authenticated users to gain remote code execution using the in browser editing feature via editing a symbolic link within a repository."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://jira.atlassian.com/browse/BSERV-10684","refsource":"CONFIRM","url":"https://jira.atlassian.com/browse/BSERV-10684"},{"name":"103488","refsource":"BID","url":"http://www.securityfocus.com/bid/103488"},{"name":"https://confluence.atlassian.com/x/3WNsO","refsource":"CONFIRM","url":"https://confluence.atlassian.com/x/3WNsO"}]}},"nvd":{"publishedDate":"2018-03-22 13:29:00","lastModifiedDate":"2018-04-20 16:57:00","problem_types":["CWE-59"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.9,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.1,"impactScore":6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.5},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":6.4,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8.0","versionEndExcluding":"5.8.2","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:*","versionStartIncluding":"4.13.0","versionEndExcluding":"5.4.8","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:*","versionStartExcluding":"5.5.0","versionEndExcluding":"5.5.8","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6.0","versionEndExcluding":"5.6.5","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:*","versionStartIncluding":"5.7.0","versionEndExcluding":"5.7.3","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"5225","Ordinal":"121182","Title":"CVE-2018-5225","CVE":"CVE-2018-5225","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"5225","Ordinal":"1","NoteData":"In browser editing in Atlassian Bitbucket Server from version 4.13.0 before 5.4.8 (the fixed version for 4.13.0 through 5.4.7), 5.5.0 before 5.5.8 (the fixed version for 5.5.x), 5.6.0 before 5.6.5 (the fixed version for 5.6.x), 5.7.0 before 5.7.3 (the fixed version for 5.7.x), and 5.8.0 before 5.8.2 (the fixed version for 5.8.x), allows authenticated users to gain remote code execution using the in browser editing feature via editing a symbolic link within a repository.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"5225","Ordinal":"2","NoteData":"2018-03-22","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"5225","Ordinal":"3","NoteData":"2018-03-26","Type":"Other","Title":"Modified"}]}}}