Atlassian Bitbucket Server是澳大利亚Atlassian公司的一款Git代码托管解决方案。该方案能够管理并审查代码,具有差异视图、JIRA集成和构建集成等功能。 Atlassian Bitbucket Server中的git repository tag rest resource存在目录遍历漏洞。远程攻击者可借助git标签名利用该漏洞读取任意文件。以下版本受到影响:Atlassian Bitbucket Server 3.7.0版本至4.14.11版本(不包括4.14.11版本)
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Atlassian | Bitbucket Server | from 3.7.0 prior to 4.14.11 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2017-18034 | Atlassian Fisheye和Crucible 跨站脚本漏洞 | |
| CVE-2017-18035 | Atlassian Fisheye和Crucible 安全漏洞 | |
| CVE-2017-18036 | Atlassian Bitbucket Server Github repository importer 安全漏洞 | |
| CVE-2017-18038 | Atlassian Bitbucket Server 路径遍历漏洞 | |
| CVE-2017-18039 | Atlassian Jira 跨站脚本漏洞 | |
| CVE-2017-18040 | Atlassian Bamboo 跨站脚本漏洞 | |
| CVE-2017-18041 | Atlassian Bamboo 跨站脚本漏洞 | |
| CVE-2017-18042 | Atlassian Bamboo 跨站请求伪造漏洞 | |
| CVE-2017-18080 | Atlassian Bamboo 跨站请求伪造漏洞 | |
| CVE-2017-18081 | Atlassian Bamboo 跨站脚本漏洞 | |
| CVE-2017-18082 | Atlassian Bamboo 跨站脚本漏洞 | |
| CVE-2017-18083 | Atlassian Confluence Server 跨站脚本漏洞 | |
| CVE-2017-18084 | Atlassian Confluence Server 跨站脚本漏洞 | |
| CVE-2017-18085 | Atlassian Confluence Server 跨站脚本漏洞 |
No comments yet