Bypass Vulnerability in Bitbucket Auto-Unapprove Plugin by Atlassian
CVE-2017-16857

8.5HIGH

Key Information:

Vendor
Atlassian
Vendor
CVE Published:
5 December 2017

Summary

The Bitbucket Auto-Unapprove Plugin has a vulnerability that allows attackers to bypass its functionality by exploiting asynchronous events on the back-end. This flaw can be leveraged through a simple brute-force method, enabling malicious actors to merge code into repositories without authorization. All versions of the Auto-Unapprove Plugin are affected, but since it is not included with Bitbucket Server, there are no specific Bitbucket versions impacted. This raises concerns about repository security and necessitates immediate attention to secure the affected plugin.

Affected Version(s)

Auto-Unapprove Plugin (for Bitbucket Server) All versions prior to version 3.0.1

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.