CVE Feed

    Dashboard / CVE / CVE-2017-16857

    CVE-2017-16857

    It is possible to bypass the bitbucket auto-unapprove plugin via minimal brute-force because it is relying on asynchronous events on the back-end. This allows an attacker to merge any code into unsuspecting repositories. This affects all versions of the auto-unapprove plugin, however since the auto-unapprove plugin is not bundled with Bitbucket Server it does not affect any particular version of Bitbucket.

    Published:Dec 5, 2017
    Last Modified:Apr 20, 2025
    EPS:Dec 5, 2017
    EPSS Score:0.00274
    CVSS Score:8.5

    Affected Products

    Vendor
    Atlassian
    Product
    Bitbucket Auto Unapprove Plugin

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High