Bypass Vulnerability in Bitbucket Auto-Unapprove Plugin by Atlassian
CVE-2017-16857
Key Information:
- Vendor
Atlassian
- Vendor
- CVE Published:
- 5 December 2017
What is CVE-2017-16857?
The Bitbucket Auto-Unapprove Plugin has a vulnerability that allows attackers to bypass its functionality by exploiting asynchronous events on the back-end. This flaw can be leveraged through a simple brute-force method, enabling malicious actors to merge code into repositories without authorization. All versions of the Auto-Unapprove Plugin are affected, but since it is not included with Bitbucket Server, there are no specific Bitbucket versions impacted. This raises concerns about repository security and necessitates immediate attention to secure the affected plugin.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Auto-Unapprove Plugin (for Bitbucket Server) All versions prior to version 3.0.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved