CVE-2020-14171

6.5MEDIUM

Key Information:

Vendor
Atlassian
Vendor
CVE Published:
9 July 2020

Summary

Atlassian Bitbucket Server from version 4.9.0 before version 7.2.4 allows remote attackers to intercept unencrypted repository import requests via a Man-in-the-Middle (MITM) attack.

Affected Version(s)

Bitbucket Server 4.9.0

Bitbucket Server < 7.2.4

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.