Learn about CVE-2017-18087 affecting Atlassian Bitbucket Server versions 5.1.0 to 5.4.1. Remote attackers can write files to disk, potentially leading to code execution. Find mitigation steps here.
Atlassian Bitbucket Server versions 5.1.0 to 5.4.1 are vulnerable to remote code execution due to a file writing issue.
Understanding CVE-2017-18087
This CVE involves a vulnerability in the download commit resource of Atlassian Bitbucket Server.
What is CVE-2017-18087?
The vulnerability allows remote attackers to write files to disk, potentially leading to code execution. It can be exploited when a vulnerable version of git is in use. Additionally, attackers can exploit an argument injection vulnerability in the 'at' parameter.
The Impact of CVE-2017-18087
Technical Details of CVE-2017-18087
The technical details of this CVE are as follows:
Vulnerability Description
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Protect your systems from CVE-2017-18087 with the following steps:
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates