CVE-2020-14171: Atlassian Bitbucket

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

Atlassian Bitbucket Server from version 4.9.0 before version 7.2.4 allows remote attackers to intercept unencrypted repository import requests via a Man-in-the-Middle (MITM) attack.

Affected products

  • Atlassian Bitbucket: from 4.9.0, before 7.2.4 (fixed in 7.2.4)

Published 2020-07-09. Last modified 2026-06-17.