GitBucket 4.23.1 contains an unauthenticated remote code execution vulnerability that allows attackers to execute arbitrary commands by exploiting weak secret token generation and insecure file upload functionality. Attackers can brute-force the Blowfish encryption key, upload a malicious JAR plugin via the git-lfs endpoint, and execute system commands through an exposed exploit endpoint.
References
| Link | Resource |
|---|---|
| https://github.com/gitbucket/gitbucket | Product |
| https://security.szurek.pl/ | Not Applicable Press/Media Coverage |
| https://www.exploit-db.com/exploits/44668 | Exploit Patch |
| https://www.vulncheck.com/advisories/gitbucket-unauthenticated-remote-code-execution | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-05-17 13:16
Updated : 2026-06-17 01:55
NVD link : CVE-2018-25332
Mitre link : CVE-2018-25332
CVE.ORG link : CVE-2018-25332
JSON object : View
Products Affected
gitbucket
- gitbucket
CWE
CWE-306
Missing Authentication for Critical Function
