AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2017-18088

MEDIUM · CVSS 4.3 EPSS 0.99%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-02-15 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2017-18088
Severity
MEDIUM
CVSS
4.3
EPSS
0.99%

Original Filing — NVD Description

Various plugin servlet resources in Atlassian Bitbucket Server before version 5.3.7 (the fixed version for 5.3.x), from version 5.4.0 before 5.4.6 (the fixed version for 5.4.x), from version 5.5.0 before 5.5.6 (the fixed version for 5.5.x), from version 5.6.0 before 5.6.3 (the fixed version for 5.6.x), from version 5.7.0 before 5.7.1 (the fixed version for 5.7.x) and before 5.8.0 allow remote attackers to conduct clickjacking attacks via framing various resources that lacked clickjacking protection.