CVE-2018-25332: critical vulnerability in GitBucket
GitBucket 4.23.1 Unauthenticated Remote Code Execution
Published · Updated
48Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 9.3epss 0.6%
exploitation probability
0.6%top 54% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
GitBucket 4.23.1 contains an unauthenticated remote code execution vulnerability that allows attackers to execute arbitrary commands by exploiting weak secret token generation and insecure file upload functionality. Attackers can brute-force the Blowfish encryption key, upload a malicious JAR plugin via the git-lfs endpoint, and execute system commands through an exposed exploit endpoint.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
gitbucket · GitBucketpublic PoCs found — 1
cve_referencewww.exploit-db.com/exploits/44668unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.