CVE-2017-18038: Atlassian Bitbucket

Medium severity, CVSS 5.3. EPSS: 1.4% chance of exploitation in the next 30 days.

The repository settings resource in Atlassian Bitbucket Server before version 5.6.0 allows remote attackers to read the first line of arbitrary files via a path traversal vulnerability through the default branch name.

Affected products

  • Atlassian Bitbucket: before 5.6.0 (fixed in 5.6.0)

Published 2018-02-02. Last modified 2026-06-17.