Uploaded image for project: 'Bitbucket Cloud'
  1. Bitbucket Cloud
  2. BCLOUD-6629

Admin privilege escalation security bug

    XMLWordPrintable

Details

    Description

      Hello,

      I believe it's possible to gain admin access to any account which hasn't got a 'premium' subscription.

      Fairly simple really, generate a invoice link to upgrade their account. The email addresses you provide automatically gain admin access to the associated account without any authorisation from the origin account.

      While it leaves a fairly good audit trail (unless you're using a stolen CC) it should allow you to escalate rights on any account.

      Hopefully I'm wrong

      Attachments

        Activity

          People

            6995b9ed1710 evzijst
            ec3d68e849ce Miles Burton
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: