Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wrg5-4633-4gg8

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.5

Описание

It is possible to bypass the bitbucket auto-unapprove plugin via minimal brute-force because it is relying on asynchronous events on the back-end. This allows an attacker to merge any code into unsuspecting repositories. This affects all versions of the auto-unapprove plugin, however since the auto-unapprove plugin is not bundled with Bitbucket Server it does not affect any particular version of Bitbucket.

It is possible to bypass the bitbucket auto-unapprove plugin via minimal brute-force because it is relying on asynchronous events on the back-end. This allows an attacker to merge any code into unsuspecting repositories. This affects all versions of the auto-unapprove plugin, however since the auto-unapprove plugin is not bundled with Bitbucket Server it does not affect any particular version of Bitbucket.

EPSS

Процентиль: 51%
0.00274
Низкий

8.5 High

CVSS3

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 8.5
nvd
около 8 лет назад

It is possible to bypass the bitbucket auto-unapprove plugin via minimal brute-force because it is relying on asynchronous events on the back-end. This allows an attacker to merge any code into unsuspecting repositories. This affects all versions of the auto-unapprove plugin, however since the auto-unapprove plugin is not bundled with Bitbucket Server it does not affect any particular version of Bitbucket.

EPSS

Процентиль: 51%
0.00274
Низкий

8.5 High

CVSS3

Дефекты

CWE-362