CVE-2017-18088: Input Validation
Various plugin servlet resources in Atlassian Bitbucket Server before version 5.3.7 (the fixed version for 5.3.x), from version 5.4.0 before 5.4.6 (the fixed version for 5.4.x), from version 5.5.0 before 5.5.6 (the fixed version for 5.5.x), from version 5.6.0 before 5.6.3 (the fixed version for 5.6.x), from version 5.7.0 before 5.7.1 (the fixed version for 5.7.x) and before 5.8.0 allow remote attackers to conduct clickjacking attacks via framing various resources that lacked clickjacking protection.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2017-18088.
What is the severity of CVE-2017-18088?
The severity of CVE-2017-18088 is medium.
Which version of Atlassian Bitbucket Server is affected by CVE-2017-18088?
Atlassian Bitbucket Server versions before 5.3.7, 5.4.6, 5.5.6, and 5.6.3 are affected by CVE-2017-18088.
How can I fix CVE-2017-18088?
To fix CVE-2017-18088, you should upgrade Atlassian Bitbucket Server to version 5.3.7, 5.4.6, 5.5.6, or 5.6.3.
Are there any references for CVE-2017-18088?
Yes, you can find references for CVE-2017-18088 at the following links: [SecurityFocus](http://www.securityfocus.com/bid/103040) and [Atlassian Jira](https://jira.atlassian.com/browse/BSERV-10594).