Various plugin servlet resources in Atlassian Bitbucket Server before version 5.3.7 (the fixed version for 5.3.x), from version 5.4.0 before 5.4.6 (the fixed version for 5.4.x), from version 5.5.0 before 5.5.6 (the fixed version for 5.5.x), from version 5.6.0 before 5.6.3 (the fixed version for 5.6.x), from version 5.7.0 before 5.7.1 (the fixed version for 5.7.x) and before 5.8.0 allow remote attackers to conduct clickjacking attacks via framing various resources that lacked clickjacking protection.
References
Link Resource
http://www.securityfocus.com/bid/103040 Third Party Advisory VDB Entry
https://jira.atlassian.com/browse/BSERV-10594 Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: atlassian

Published: 2018-02-15T13:00:00

Updated: 2018-02-16T10:57:01

Reserved: 2018-02-01T00:00:00


Link: CVE-2017-18088

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-02-15T13:29:00.297

Modified: 2018-03-15T17:02:49.493


Link: CVE-2017-18088

JSON object: View

cve-icon Redhat Information

No data.

CWE