In browser editing in Atlassian Bitbucket Server from version 4.13.0 before 5.4.8 (the fixed version for 4.13.0 through 5.4.7), 5.5.0 before 5.5.8 (the fixed version for 5.5.x), 5.6.0 before 5.6.5 (the fixed version for 5.6.x), 5.7.0 before 5.7.3 (the fixed version for 5.7.x), and 5.8.0 before 5.8.2 (the fixed version for 5.8.x), allows authenticated users to gain remote code execution using the in browser editing feature via editing a symbolic link within a repository.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HAtlassian Bitbucket
APPAtlassian4.13.0 – 5.4.8 (excl.)< 5.5.85.6.0 – 5.6.5 (excl.)5.7.0 – 5.7.3 (excl.)5.8.0 – 5.8.2 (excl.)
Related vulnerabilities
Command injection w Bitbucket Server i Data Center przez zmienne środowiskowe
Atlassian — pominięcie Servlet Filters umożliwia auth bypass i XSS
Command injection w Atlassian Bitbucket Server i Data Center via commit diff endpoint
RCE przez path traversal w narzędziu migracji Atlassian Bitbucket Data Center
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version...