CVE-2017-18036 describes a Server-Side Request Forgery (SSRF) vulnerability in Atlassian Bitbucket Server versions prior to 5.3.0, specifically within its GitHub repository importer. This medium-severity vulnerability (CVSS 4.3) allows authenticated remote attackers to probe internal networks for open ports, potentially revealing network architecture. While it has no known active exploits, public exploit code, or significant community discussion, its presence in a widely used product warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.3.0CPE matchmatch criteria | cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.