CVE-2018-25332

GitBucket 4.23.1 contains an unauthenticated remote code execution vulnerability that allows attackers to execute arbitrary commands by exploiting weak secret token generation and insecure file upload functionality. Attackers can brute-force the Blowfish encryption key, upload a malicious JAR plugin via the git-lfs endpoint, and execute system commands through an exposed exploit endpoint.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gitbucket:gitbucket:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-05-17 13:16

Updated : 2026-06-17 01:55


NVD link : CVE-2018-25332

Mitre link : CVE-2018-25332

CVE.ORG link : CVE-2018-25332


JSON object : View

Products Affected

gitbucket

  • gitbucket
CWE
CWE-306

Missing Authentication for Critical Function