CVE-2017-18038

Publication date

2018-02-02 14:00:00

Family

atlassian

State

PUBLISHED

Description

The repository settings resource in Atlassian Bitbucket Server before version 5.6.0 allows remote attackers to read the first line of arbitrary files via a path traversal vulnerability through the default branch name.