CVE-2018-25332 PUBLISHED

GitBucket 4.23.1 Unauthenticated Remote Code Execution

Assigner: VulnCheck
Reserved: 17.05.2026 Published: 17.05.2026 Updated: 17.05.2026

GitBucket 4.23.1 contains an unauthenticated remote code execution vulnerability that allows attackers to execute arbitrary commands by exploiting weak secret token generation and insecure file upload functionality. Attackers can brute-force the Blowfish encryption key, upload a malicious JAR plugin via the git-lfs endpoint, and execute system commands through an exposed exploit endpoint.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor gitbucket
Product GitBucket
Versions
  • Version 4.23.1 is affected

Credits

  • Kacper Szurek finder

References

Problem Types

  • Missing Authentication for Critical Function CWE