CVE-2017-18036: Atlassian Bitbucket
Medium severity, CVSS 4.3. EPSS: 0.9% chance of exploitation in the next 30 days.
The Github repository importer in Atlassian Bitbucket Server before version 5.3.0 allows remote attackers to determine if a service they could not otherwise reach has open ports via a Server Side Request Forgery (SSRF) vulnerability.
Affected products
- Atlassian Bitbucket: before 5.3.0 (fixed in 5.3.0)
Published 2018-02-02. Last modified 2026-06-17.