Vulnerabilities (CVE)

Filtered by vendor Atlassian Subscribe
Filtered by product Bitbucket Auto Unapprove Plugin
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-16857 1 Atlassian 1 Bitbucket Auto Unapprove Plugin 2024-11-21 6.0 MEDIUM 8.5 HIGH
It is possible to bypass the bitbucket auto-unapprove plugin via minimal brute-force because it is relying on asynchronous events on the back-end. This allows an attacker to merge any code into unsuspecting repositories. This affects all versions of the auto-unapprove plugin, however since the auto-unapprove plugin is not bundled with Bitbucket Server it does not affect any particular version of Bitbucket.