« Volver al listado

CVE-2017-16857

Estado: ModificadaAlta (8.5)—

It is possible to bypass the bitbucket auto-unapprove plugin via minimal brute-force because it is relying on asynchronous events on the back-end. This allows an attacker to merge any code into unsuspecting repositories. This affects all versions of the auto-unapprove plugin, however since the auto-unapprove plugin is not bundled with Bitbucket Server it does not affect any particular version of Bitbucket.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-16857",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:S/C:P/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.0",
          "baseScore": 8.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@atlassian.com",
      "affectedData": [
        {
          "vendor": "Atlassian",
          "product": "Auto-Unapprove Plugin (for Bitbucket Server)",
          "versions": [
            {
              "status": "affected",
              "version": "All versions prior to version 3.0.1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-12-05T16:29:00.453",
  "references": [
    {
      "url": "https://jira.atlassian.com/browse/BSERV-10439",
      "tags": [
        "Issue Tracking",
        "Vendor Advisory"
      ],
      "source": "security@atlassian.com"
    },
    {
      "url": "https://jira.atlassian.com/browse/BSERV-10439",
      "tags": [
        "Issue Tracking",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-362"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "It is possible to bypass the bitbucket auto-unapprove plugin via minimal brute-force because it is relying on asynchronous events on the back-end. This allows an attacker to merge any code into unsuspecting repositories. This affects all versions of the auto-unapprove plugin, however since the auto-unapprove plugin is not bundled with Bitbucket Server it does not affect any particular version of Bitbucket."
    },
    {
      "lang": "es",
      "value": "Es posible omitir el plugin bitbucket auto-unapprove mediante fuerza bruta mínima, ya que depende de eventos asíncronos en el back end. Esto permite que un atacante combine cualquier código en repositorios no planeados. Esto afecta a todas las versiones del plugin auto-unapprove; sin embargo, debido a que el plugin auto-unapprove no está agrupado con Bitbucket Server, no afecta a ninguna versión en particular de Bitbucket."
    }
  ],
  "lastModified": "2026-06-17T01:10:02.050",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:atlassian:bitbucket_auto_unapprove_plugin:1.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "97911FE2-5F86-4BE3-AB28-9816EB9CAEDA"
            },
            {
              "criteria": "cpe:2.3:a:atlassian:bitbucket_auto_unapprove_plugin:1.0.0:beta1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "53F394B8-F666-4D37-9AC9-7F5397A405E1"
            },
            {
              "criteria": "cpe:2.3:a:atlassian:bitbucket_auto_unapprove_plugin:1.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6786304B-5EC4-4EA8-88AB-7DC3518DACB2"
            },
            {
              "criteria": "cpe:2.3:a:atlassian:bitbucket_auto_unapprove_plugin:1.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FA4C63A4-4315-4083-902D-4C5AA056AE9B"
            },
            {
              "criteria": "cpe:2.3:a:atlassian:bitbucket_auto_unapprove_plugin:2.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8830EDAD-E6B0-4A27-A455-97E14374AF4F"
            },
            {
              "criteria": "cpe:2.3:a:atlassian:bitbucket_auto_unapprove_plugin:2.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B84B6B9F-E2F9-44E9-AA13-B59F975991A0"
            },
            {
              "criteria": "cpe:2.3:a:atlassian:bitbucket_auto_unapprove_plugin:2.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "607F4C07-6457-4D97-A9AB-1D0EF98B035C"
            },
            {
              "criteria": "cpe:2.3:a:atlassian:bitbucket_auto_unapprove_plugin:2.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "16A0B68D-5682-40A8-9755-D85902BCDD63"
            },
            {
              "criteria": "cpe:2.3:a:atlassian:bitbucket_auto_unapprove_plugin:2.1.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1035851A-D3DF-4A66-B807-1BF85BDF4260"
            },
            {
              "criteria": "cpe:2.3:a:atlassian:bitbucket_auto_unapprove_plugin:2.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C7E4D548-247D-41D7-AEEC-606C3A1E0AA7"
            },
            {
              "criteria": "cpe:2.3:a:atlassian:bitbucket_auto_unapprove_plugin:3.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "35951C11-94DF-4620-9007-D5F3665502EE"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@atlassian.com"
}