📦

bitbucket_auto_unapprove_plugin

Vendor: atlassian

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 0 Remote Access
Total CVEs 18 Total Indexed
Avg. EPSS 0.59% Exploit Prob.
Latest CVE CVE-2017-16857 Dec 05

Security Vulnerability Index

Page 1 / 2
8.5 CVSS

It is possible to bypass the bitbucket auto-unapprove plugin via minimal brute-force because it is relying on asynchronous events on the back-end. This allows an attacker to merge any code into unsuspecting repositories. This affects all versions of the auto-unapprove plugin, however since the auto-unapprove plugin is not bundled with Bitbucket Server it does not affect any particular version of Bitbucket.

EPSS: 0.59%