Vulnerability Details CVE-2018-5225
In browser editing in Atlassian Bitbucket Server from version 4.13.0 before 5.4.8 (the fixed version for 4.13.0 through 5.4.7), 5.5.0 before 5.5.8 (the fixed version for 5.5.x), 5.6.0 before 5.6.5 (the fixed version for 5.6.x), 5.7.0 before 5.7.3 (the fixed version for 5.7.x), and 5.8.0 before 5.8.2 (the fixed version for 5.8.x), allows authenticated users to gain remote code execution using the in browser editing feature via editing a symbolic link within a repository.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.028
EPSS Ranking 85.7%
CVSS Severity
CVSS v3 Score 9.9
CVSS v2 Score 6.5
Products affected by CVE-2018-5225
-
cpe:2.3:a:atlassian:bitbucket:4.13.0
-
cpe:2.3:a:atlassian:bitbucket:4.13.1
-
cpe:2.3:a:atlassian:bitbucket:4.14.0
-
cpe:2.3:a:atlassian:bitbucket:4.14.1
-
cpe:2.3:a:atlassian:bitbucket:4.14.10
-
cpe:2.3:a:atlassian:bitbucket:4.14.11
-
cpe:2.3:a:atlassian:bitbucket:4.14.12
-
cpe:2.3:a:atlassian:bitbucket:4.14.2
-
cpe:2.3:a:atlassian:bitbucket:4.14.3
-
cpe:2.3:a:atlassian:bitbucket:4.14.4
-
cpe:2.3:a:atlassian:bitbucket:4.14.5
-
cpe:2.3:a:atlassian:bitbucket:4.14.6
-
cpe:2.3:a:atlassian:bitbucket:4.14.7
-
cpe:2.3:a:atlassian:bitbucket:4.14.8
-
cpe:2.3:a:atlassian:bitbucket:4.14.9
-
cpe:2.3:a:atlassian:bitbucket:5.0.0
-
cpe:2.3:a:atlassian:bitbucket:5.0.1
-
cpe:2.3:a:atlassian:bitbucket:5.0.10
-
cpe:2.3:a:atlassian:bitbucket:5.0.2
-
cpe:2.3:a:atlassian:bitbucket:5.0.3
-
cpe:2.3:a:atlassian:bitbucket:5.0.4
-
cpe:2.3:a:atlassian:bitbucket:5.0.5
-
cpe:2.3:a:atlassian:bitbucket:5.0.6
-
cpe:2.3:a:atlassian:bitbucket:5.0.7
-
cpe:2.3:a:atlassian:bitbucket:5.0.8
-
cpe:2.3:a:atlassian:bitbucket:5.0.9
-
cpe:2.3:a:atlassian:bitbucket:5.1.0
-
cpe:2.3:a:atlassian:bitbucket:5.1.1
-
cpe:2.3:a:atlassian:bitbucket:5.1.2
-
cpe:2.3:a:atlassian:bitbucket:5.1.3
-
cpe:2.3:a:atlassian:bitbucket:5.1.4
-
cpe:2.3:a:atlassian:bitbucket:5.1.5
-
cpe:2.3:a:atlassian:bitbucket:5.1.6
-
cpe:2.3:a:atlassian:bitbucket:5.1.7
-
cpe:2.3:a:atlassian:bitbucket:5.1.8
-
cpe:2.3:a:atlassian:bitbucket:5.1.9
-
cpe:2.3:a:atlassian:bitbucket:5.2.0
-
cpe:2.3:a:atlassian:bitbucket:5.2.1
-
cpe:2.3:a:atlassian:bitbucket:5.2.2
-
cpe:2.3:a:atlassian:bitbucket:5.2.3
-
cpe:2.3:a:atlassian:bitbucket:5.2.4
-
cpe:2.3:a:atlassian:bitbucket:5.2.5
-
cpe:2.3:a:atlassian:bitbucket:5.2.6
-
cpe:2.3:a:atlassian:bitbucket:5.2.7
-
cpe:2.3:a:atlassian:bitbucket:5.2.8
-
cpe:2.3:a:atlassian:bitbucket:5.3.0
-
cpe:2.3:a:atlassian:bitbucket:5.3.1
-
cpe:2.3:a:atlassian:bitbucket:5.3.2
-
cpe:2.3:a:atlassian:bitbucket:5.3.3
-
cpe:2.3:a:atlassian:bitbucket:5.3.4
-
cpe:2.3:a:atlassian:bitbucket:5.3.5
-
cpe:2.3:a:atlassian:bitbucket:5.3.6
-
cpe:2.3:a:atlassian:bitbucket:5.3.7
-
cpe:2.3:a:atlassian:bitbucket:5.4.0
-
cpe:2.3:a:atlassian:bitbucket:5.4.1
-
cpe:2.3:a:atlassian:bitbucket:5.4.2
-
cpe:2.3:a:atlassian:bitbucket:5.4.3
-
cpe:2.3:a:atlassian:bitbucket:5.4.4
-
cpe:2.3:a:atlassian:bitbucket:5.4.6
-
cpe:2.3:a:atlassian:bitbucket:5.4.7
-
cpe:2.3:a:atlassian:bitbucket:5.5.1
-
cpe:2.3:a:atlassian:bitbucket:5.5.2
-
cpe:2.3:a:atlassian:bitbucket:5.5.3
-
cpe:2.3:a:atlassian:bitbucket:5.5.4
-
cpe:2.3:a:atlassian:bitbucket:5.5.5
-
cpe:2.3:a:atlassian:bitbucket:5.5.6
-
cpe:2.3:a:atlassian:bitbucket:5.5.7
-
cpe:2.3:a:atlassian:bitbucket:5.6.0
-
cpe:2.3:a:atlassian:bitbucket:5.6.1
-
cpe:2.3:a:atlassian:bitbucket:5.6.2
-
cpe:2.3:a:atlassian:bitbucket:5.6.3
-
cpe:2.3:a:atlassian:bitbucket:5.6.4
-
cpe:2.3:a:atlassian:bitbucket:5.7.0
-
cpe:2.3:a:atlassian:bitbucket:5.7.1
-
cpe:2.3:a:atlassian:bitbucket:5.7.2
-
cpe:2.3:a:atlassian:bitbucket:5.8.0
-
cpe:2.3:a:atlassian:bitbucket:5.8.1