6
CVSSv2

CVE-2017-16857

Published: 05/12/2017 Updated: 03/10/2019
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
CVSS v3 Base Score: 8.5 | Impact Score: 6 | Exploitability Score: 1.8
VMScore: 534
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

It is possible to bypass the bitbucket auto-unapprove plugin via minimal brute-force because it is relying on asynchronous events on the back-end. This allows an malicious user to merge any code into unsuspecting repositories. This affects all versions of the auto-unapprove plugin, however since the auto-unapprove plugin is not bundled with Bitbucket Server it does not affect any particular version of Bitbucket.

Vulnerable Product Search on Vulmon Subscribe to Product

atlassian bitbucket auto unapprove plugin 1.1.0

atlassian bitbucket auto unapprove plugin 2.0.1

atlassian bitbucket auto unapprove plugin 2.2.0

atlassian bitbucket auto unapprove plugin 1.0.0

atlassian bitbucket auto unapprove plugin 1.2.0

atlassian bitbucket auto unapprove plugin 3.0.0

atlassian bitbucket auto unapprove plugin 2.0.2

atlassian bitbucket auto unapprove plugin 2.0.4

atlassian bitbucket auto unapprove plugin 2.1.1

atlassian bitbucket auto unapprove plugin 2.1.3