{"id":"CVE-2018-25332","details":"GitBucket 4.23.1 contains an unauthenticated remote code execution vulnerability that allows attackers to execute arbitrary commands by exploiting weak secret token generation and insecure file upload functionality. Attackers can brute-force the Blowfish encryption key, upload a malicious JAR plugin via the git-lfs endpoint, and execute system commands through an exposed exploit endpoint.","modified":"2026-07-08T19:01:52.383568Z","published":"2026-05-17T13:16:44.840Z","references":[{"type":"WEB","url":"https://security.szurek.pl/"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/gitbucket-unauthenticated-remote-code-execution"},{"type":"FIX","url":"https://www.exploit-db.com/exploits/44668"},{"type":"PACKAGE","url":"https://github.com/gitbucket/gitbucket"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gitbucket/gitbucket","events":[{"introduced":"0"},{"fixed":"5913bcd3095e7e7b70982a442286fff08f4ec704"}],"database_specific":{"cpe":"cpe:2.3:a:gitbucket:gitbucket:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"4.24.0"}],"source":"CPE_RANGE"}}],"versions":["4.23.1","4.23.0","4.22.0","4.21.2","4.21.1","4.21.0","4.20.0","4.19.2","4.19.1","4.19.0","4.18.0","4.17.0","4.16.0","4.15.0","4.14","4.13","4.12","4.11","4.10","4.9","4.8","4.7.1","4.7","4.6","4.5","4.4","4.3","4.2.1","4.2","4.1","4.0","3.14","3.13","3.12","3.11","3.10","3.9","3.8","3.7","3.6","3.5","3.4","3.3","3.2","3.1.1","3.1","3.0","2.8","2.7","2.6","2.4.1","2.4","2.3","2.2","2.1","2.0","1.13","1.12","1.10","1.9","1.8","1.7","1.2","1.1","1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-25332.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}]}