First published: Mon Apr 10 2017(Updated: )
Atlassian Bitbucket Server before 4.7.1 allows remote attackers to read the first line of an arbitrary file via a directory traversal attack on the pull requests resource.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Bitbucket | <4.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4320 is classified as a high severity vulnerability due to its potential to allow unauthorized file access.
To fix CVE-2016-4320, update Atlassian Bitbucket Server to version 4.7.1 or later.
CVE-2016-4320 involves a directory traversal attack that allows unauthorized access to file contents.
CVE-2016-4320 affects all versions of Atlassian Bitbucket Server prior to 4.7.1.
Yes, CVE-2016-4320 can be exploited remotely by attackers without authentication.