<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Bitbucket (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/bitbucket.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/bitbucket-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Bitbucket (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:42 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-3515 – A vulnerability in the `GitHubRepository` block of the `prefect-github` integrat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3515</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3515</guid>
    <pubDate>Sun, 24 May 2026 05:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3515</strong></p>
  <p>A vulnerability in the `GitHubRepository` block of the `prefect-github` integration in Prefect version 3.6.18 allows an attacker to inject arbitrary git command-line options via the `reference` field. The `reference` field is concatenated directly into a `git clone` command string without proper sanitization, and then parsed by `shlex.split()`. This enables injection of options such as `-c`, lead…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-88</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3515">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-41574 – Nhost is an open source Firebase alternative with GraphQL. Prior to version 0.49...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41574</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41574</guid>
    <pubDate>Fri, 08 May 2026 15:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-41574</strong></p>
  <p>Nhost is an open source Firebase alternative with GraphQL. Prior to version 0.49.1, Nhost automatically links an incoming OAuth identity to an existing Nhost account when the email addresses match. This is only safe when the email has been verified by the OAuth provider. Nhost's controller trusts a profile.EmailVerified boolean that is set by each provider adapter. The vulnerability is that sever…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41574">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61916 – Spinnaker is an open source, multi-cloud continuous delivery platform. Versions ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61916</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61916</guid>
    <pubDate>Mon, 05 Jan 2026 22:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61916</strong></p>
  <p>Spinnaker is an open source, multi-cloud continuous delivery platform. Versions prior to 2025.1.6, 2025.2.3, and 2025.3.0 are vulnerable to server-side request forgery. The primary impact is allowing users to fetch data from a remote URL. This data can be then injected into spinnaker pipelines via helm or other methods to extract things LIKE idmsv1 authentication data. This also includes calling…</p>
  <p><strong>CVSS:</strong> 7.9 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61916">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-59531 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59531</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59531</guid>
    <pubDate>Wed, 01 Oct 2025 21:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-59531</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions 1.2.0 through 1.8.7, 2.0.0-rc1 through 2.14.19, 3.0.0-rc1 through 3.2.0-rc1, 3.1.7 and 3.0.18 are vulnerable to malicious API requests which can crash the API server and cause denial of service to legitimate clients. Without a configured webhook.bitbucketserver.secret, Argo CD's /api/webhook endpoint crashes when r…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-703</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59531">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-24398 – Jenkins Bitbucket Server Integration Plugin 2.1.0 through 4.1.3 (both inclusive)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24398</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24398</guid>
    <pubDate>Wed, 22 Jan 2025 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-24398</strong></p>
  <p>Jenkins Bitbucket Server Integration Plugin 2.1.0 through 4.1.3 (both inclusive) allows attackers to craft URLs that would bypass the CSRF protection of any target URL in Jenkins.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24398">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-4024 – An issue has been discovered in GitLab CE/EE affecting all versions starting fro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-4024</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-4024</guid>
    <pubDate>Thu, 25 Apr 2024 14:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-4024</strong></p>
  <p>An issue has been discovered in GitLab CE/EE affecting all versions starting from 7.8 before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1. Under certain conditions, an attacker with their Bitbucket account credentials may be able to take over a GitLab account linked to another user's Bitbucket account, if Bitbucket is used as an OAuth 2.…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-302</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-4024">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-50931 – An issue was discovered in savignano S/Notify before 2.0.1 for Bitbucket. While ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-50931</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-50931</guid>
    <pubDate>Tue, 09 Jan 2024 07:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-50931</strong></p>
  <p>An issue was discovered in savignano S/Notify before 2.0.1 for Bitbucket. While an administrative user is logged on, the configuration settings of S/Notify can be modified via a CSRF attack. The injection could be initiated by the administrator clicking a malicious link in an email or by visiting a malicious website. If executed while an administrator is logged on to Bitbucket, an attacker could…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-50931">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-22513 – This High severity RCE (Remote Code Execution) vulnerability was introduced in v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22513</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22513</guid>
    <pubDate>Tue, 19 Sep 2023 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-22513</strong></p>
  <p>This High severity RCE (Remote Code Execution) vulnerability was introduced in version 8.0.0 of Bitbucket Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.5, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires no user interaction. Atlas…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22513">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-41937 – Jenkins Bitbucket Push and Pull Request Plugin 2.4.0 through 2.8.3 (both inclusi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41937</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41937</guid>
    <pubDate>Wed, 06 Sep 2023 13:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-41937</strong></p>
  <p>Jenkins Bitbucket Push and Pull Request Plugin 2.4.0 through 2.8.3 (both inclusive) trusts values provided in the webhook payload, including certain URLs, and uses configured Bitbucket credentials to connect to those URLs, allowing attackers to capture Bitbucket credentials stored in Jenkins by sending a crafted webhook payload.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41937">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-24427 – Jenkins Bitbucket OAuth Plugin 0.12 and earlier does not invalidate the previous...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-24427</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-24427</guid>
    <pubDate>Thu, 26 Jan 2023 21:18:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-24427</strong></p>
  <p>Jenkins Bitbucket OAuth Plugin 0.12 and earlier does not invalidate the previous session on login.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-384</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24427">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-43781 – There is a command injection vulnerability using environment variables in Bitbuc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-43781</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-43781</guid>
    <pubDate>Thu, 17 Nov 2022 00:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-43781</strong></p>
  <p>There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the Bitbucket Server and Data Center instance has enabled “Allow public signup”.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-43781">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-36804 – Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 befor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-36804</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-36804</guid>
    <pubDate>Thu, 25 Aug 2022 06:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-36804</strong></p>
  <p>Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21.4, from version 8.0.0 before version 8.0.3, from version 8.1.0 before version 8.1.3, and from version 8.2.0 before version 8.2.2, and from version 8.3.0 before 8.3.1 allows remote attackers with read permissions to a p…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-36804">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-26137 – A vulnerability in multiple Atlassian products allows a remote, unauthenticated ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-26137</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-26137</guid>
    <pubDate>Wed, 20 Jul 2022 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-26137</strong></p>
  <p>A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security issue associated with this vulnerability: Cross-origin resource sharing (CORS) bypass. Sending a specially crafted HTTP request can invoke the Servl…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-180</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-26137">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-26136 – A vulnerability in multiple Atlassian products allows a remote, unauthenticated ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-26136</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-26136</guid>
    <pubDate>Wed, 20 Jul 2022 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-26136</strong></p>
  <p>A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulnerability can result in authentication bypass and cross-site scripting. Atlassian has released updates that fix the root cause of this vulnerability, b…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-180</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-26136">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-26133 – SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-26133</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-26133</guid>
    <pubDate>Wed, 20 Apr 2022 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-26133</strong></p>
  <p>SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6, 7.18.0 and later prior to 7.18.4, 7.19.0 and later prior to 7.19.4, and 7.20.0 allow a remote, unauthenticated attacker to execute arbitrary code via Java deserialization.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-26133">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-20619 – A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket Branch So...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-20619</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-20619</guid>
    <pubDate>Wed, 12 Jan 2022 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-20619</strong></p>
  <p>A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket Branch Source Plugin 737.vdf9dc06105be and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-20619">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-37843 – The resolution SAML SSO apps for Atlassian products allow a remote attacker to l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-37843</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-37843</guid>
    <pubDate>Mon, 02 Aug 2021 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-37843</strong></p>
  <p>The resolution SAML SSO apps for Atlassian products allow a remote attacker to login to a user account when only the username is known (i.e., no other authentication is provided). The fixed versions are for Jira: 3.6.6.1, 4.0.12, 5.0.5; for Confluence 3.6.6, 4.0.12, 5.0.5; for Bitbucket 2.5.9, 3.6.6, 4.0.12, 5.0.5; for Bamboo 2.5.9, 3.6.6, 4.0.12, 5.0.5; and for Fisheye 2.5.9.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-37843">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36233 – The Microsoft Windows Installer for Atlassian Bitbucket Server and Data Center b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36233</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36233</guid>
    <pubDate>Thu, 18 Feb 2021 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36233</strong></p>
  <p>The Microsoft Windows Installer for Atlassian Bitbucket Server and Data Center before version 6.10.9, 7.x before 7.6.4, and from version 7.7.0 before 7.10.1 allows local attackers to escalate privileges because of weak permissions on the installation directory.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36233">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-20097 – Bitbucket Server and Bitbucket Data Center versions starting from 1.0.0 before 5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-20097</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-20097</guid>
    <pubDate>Wed, 15 Jan 2020 21:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-20097</strong></p>
  <p>Bitbucket Server and Bitbucket Data Center versions starting from 1.0.0 before 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.1.9, from version 6.2.0 before 6.2.7, from version 6.3.0 before 6.3.6, from version 6.4.0 before 6.4.4, from version 6.5.0 before 6.5.3, from version 6.6.0 before 6.6.3, from version 6.7.0 before 6.7.3, from version 6.8.0 before 6.8.2, from version…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-20097">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-15012 – Bitbucket Server and Bitbucket Data Center from version 4.13. before 5.16.11, fr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15012</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15012</guid>
    <pubDate>Wed, 15 Jan 2020 21:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-15012</strong></p>
  <p>Bitbucket Server and Bitbucket Data Center from version 4.13. before 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.1.9, from version 6.2.0 before 6.2.7, from version 6.3.0 before 6.3.6, from version 6.4.0 before 6.4.4, from version 6.5.0 before 6.5.3, from version 6.6.0 before 6.6.3, from version 6.7.0 before 6.7.3, from version 6.8.0 before 6.8.2, from version 6.9.0 befo…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15012">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-15010 – Bitbucket Server and Bitbucket Data Center versions starting from version 3.0.0 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15010</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15010</guid>
    <pubDate>Wed, 15 Jan 2020 21:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-15010</strong></p>
  <p>Bitbucket Server and Bitbucket Data Center versions starting from version 3.0.0 before version 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.1.9, from version 6.2.0 before 6.2.7, from version 6.3.0 before 6.3.6, from version 6.4.0 before 6.4.4, from version 6.5.0 before 6.5.3, from version 6.6.0 before 6.6.3, from version 6.7.0 before 6.7.3, from version 6.8.0 before 6.8.…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15010">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-13347 – An issue was discovered in the SAML Single Sign On (SSO) plugin for several Atla...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-13347</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-13347</guid>
    <pubDate>Fri, 13 Dec 2019 13:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-13347</strong></p>
  <p>An issue was discovered in the SAML Single Sign On (SSO) plugin for several Atlassian products affecting versions 3.1.0 through 3.2.2 for Jira and Confluence, versions 2.4.0 through 3.0.3 for Bitbucket, and versions 2.4.0 through 2.5.2 for Bamboo. It allows locally disabled users to reactivate their accounts just by browsing the affected Jira/Confluence/Bitbucket/Bamboo instance, even when the ap…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-13347">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-10460 – Jenkins Bitbucket OAuth Plugin 0.9 and earlier stored credentials unencrypted in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10460</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10460</guid>
    <pubDate>Wed, 23 Oct 2019 13:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-10460</strong></p>
  <p>Jenkins Bitbucket OAuth Plugin 0.9 and earlier stored credentials unencrypted in the global config.xml configuration file on the Jenkins master where they could be viewed by users with access to the master file system.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10460">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-15000 – The commit diff rest endpoint in Bitbucket Server and Data Center before 5.16.10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15000</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15000</guid>
    <pubDate>Thu, 19 Sep 2019 15:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-15000</strong></p>
  <p>The commit diff rest endpoint in Bitbucket Server and Data Center before 5.16.10 (the fixed version for 5.16.x ), from 6.0.0 before 6.0.10 (the fixed version for 6.0.x), from 6.1.0 before 6.1.8 (the fixed version for 6.1.x), from 6.2.0 before 6.2.6 (the fixed version for 6.2.x), from 6.3.0 before 6.3.5 (the fixed version for 6.3.x), from 6.4.0 before 6.4.3 (the fixed version for 6.4.x), and from…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15000">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-6788 – An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-6788</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-6788</guid>
    <pubDate>Mon, 09 Sep 2019 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-6788</strong></p>
  <p>An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 3 of 6). For installations using GitHub or Bitbucket OAuth integrations, it is possible to use a covert redirect to obtain the user OAuth token for those services.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-6788">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-1010268 – Ladon since 0.6.1 (since ebef0aae48af78c159b6fce81bc6f5e7e0ddb059) is affected b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-1010268</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-1010268</guid>
    <pubDate>Thu, 18 Jul 2019 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-1010268</strong></p>
  <p>Ladon since 0.6.1 (since ebef0aae48af78c159b6fce81bc6f5e7e0ddb059) is affected by: XML External Entity (XXE). The impact is: Information Disclosure, reading files and reaching internal network endpoints. The component is: SOAP request handlers. For instance: https://bitbucket.org/jakobsg/ladon/src/42944fc012a3a48214791c120ee5619434505067/src/ladon/interfaces/soap.py#lines-688. The attack vector i…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-1010268">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-3397 – Atlassian Bitbucket Data Center licensed instances starting with version 5.13.0 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3397</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3397</guid>
    <pubDate>Mon, 03 Jun 2019 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-3397</strong></p>
  <p>Atlassian Bitbucket Data Center licensed instances starting with version 5.13.0 before 5.13.6 (the fixed version for 5.13.x), from 5.14.0 before 5.14.4 (fixed version for 5.14.x), from 5.15.0 before 5.15.3 (fixed version for 5.15.x), from 5.16.0 before 5.16.3 (fixed version for 5.16.x), from 6.0.0 before 6.0.3 (fixed version for 6.0.x), and from 6.1.0 before 6.1.2 (the fixed version for 6.1.x) al…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3397">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-1003057 – Jenkins Bitbucket Approve Plugin stores credentials unencrypted in its global co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-1003057</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-1003057</guid>
    <pubDate>Thu, 04 Apr 2019 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-1003057</strong></p>
  <p>Jenkins Bitbucket Approve Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-311</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-1003057">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-5225 – In browser editing in Atlassian Bitbucket Server from version 4.13.0 before 5.4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-5225</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-5225</guid>
    <pubDate>Thu, 22 Mar 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-5225</strong></p>
  <p>In browser editing in Atlassian Bitbucket Server from version 4.13.0 before 5.4.8 (the fixed version for 4.13.0 through 5.4.7), 5.5.0 before 5.5.8 (the fixed version for 5.5.x), 5.6.0 before 5.6.5 (the fixed version for 5.6.x), 5.7.0 before 5.7.3 (the fixed version for 5.7.x), and 5.8.0 before 5.8.2 (the fixed version for 5.8.x), allows authenticated users to gain remote code execution using the…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-5225">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-18087 – The download commit resource in Atlassian Bitbucket Server from version 5.1.0 be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-18087</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-18087</guid>
    <pubDate>Thu, 15 Feb 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-18087</strong></p>
  <p>The download commit resource in Atlassian Bitbucket Server from version 5.1.0 before version 5.1.7, from version 5.2.0 before version 5.2.5, from version 5.3.0 before version 5.3.3 and from version 5.4.0 before version 5.4.1 allows remote attackers to write files to disk potentially allowing them to gain code execution, exploit CVE-2017-1000117 if a vulnerable version of git is in use, and or det…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-18087">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-16857 – It is possible to bypass the bitbucket auto-unapprove plugin via minimal brute-f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-16857</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-16857</guid>
    <pubDate>Tue, 05 Dec 2017 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-16857</strong></p>
  <p>It is possible to bypass the bitbucket auto-unapprove plugin via minimal brute-force because it is relying on asynchronous events on the back-end. This allows an attacker to merge any code into unsuspecting repositories. This affects all versions of the auto-unapprove plugin, however since the auto-unapprove plugin is not bundled with Bitbucket Server it does not affect any particular version of…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-16857">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-6668 – The Atlassian Hipchat Integration Plugin for Bitbucket Server 6.26.0 before 6.27...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6668</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6668</guid>
    <pubDate>Mon, 23 Jan 2017 21:59:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-6668</strong></p>
  <p>The Atlassian Hipchat Integration Plugin for Bitbucket Server 6.26.0 before 6.27.5, 6.28.0 before 7.3.7, and 7.4.0 before 7.8.17; Confluence HipChat plugin 6.26.0 before 7.8.17; and HipChat for JIRA plugin 6.26.0 before 7.8.17 allows remote attackers to obtain the secret key for communicating with HipChat instances by reading unspecified pages.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6668">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
