CVE-2017-18088: Atlassian Bitbucket

Medium severity, CVSS 4.3. EPSS: 1% chance of exploitation in the next 30 days.

Various plugin servlet resources in Atlassian Bitbucket Server before version 5.3.7 (the fixed version for 5.3.x), from version 5.4.0 before 5.4.6 (the fixed version for 5.4.x), from version 5.5.0 before 5.5.6 (the fixed version for 5.5.x), from version 5.6.0 before 5.6.3 (the fixed version for 5.6.x), from version 5.7.0 before 5.7.1 (the fixed version for 5.7.x) and before 5.8.0 allow remote attackers to conduct clickjacking attacks via framing various resources that lacked clickjacking protection.

Affected products

  • Atlassian Bitbucket: from 5.3.0, before 5.3.7 (fixed in 5.3.7); from 5.4.0, before 5.4.6 (fixed in 5.4.6); from 5.5.0, before 5.5.6 (fixed in 5.5.6); from 5.6.0, before 5.6.3 (fixed in 5.6.3); from 5.7.0, before 5.7.1 (fixed in 5.7.1)

Published 2018-02-15. Last modified 2026-06-17.