Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2018-5225

In browser editing in Atlassian Bitbucket Server from version 4.13.0 before 5.4.8 (the fixed version for 4.13.0 through 5.4.7), 5.5.0 before 5.5.8 (the fixed version for 5.5.x), 5.6.0 before 5.6.5 (the fixed version for 5.6.x), 5.7.0 before 5.7.3 (the fixed version for 5.7.x), and 5.8.0 before 5.8.2 (the fixed version for 5.8.x), allows authenticated users to gain remote code execution using the in browser editing feature via editing a symbolic link within a repository.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.028
EPSS Ranking 85.7%
CVSS Severity
CVSS v3 Score 9.9
CVSS v2 Score 6.5
Products affected by CVE-2018-5225


Contact Us

Shodan ® - All rights reserved