Atlassian Bitbucket Data Center licensed instances starting with version 5.13.0 before 5.13.6 (the fixed version for 5.13.x), from 5.14.0 before 5.14.4 (fixed version for 5.14.x), from 5.15.0 before 5.15.3 (fixed version for 5.15.x), from 5.16.0 before 5.16.3 (fixed version for 5.16.x), from 6.0.0 before 6.0.3 (fixed version for 6.0.x), and from 6.1.0 before 6.1.2 (the fixed version for 6.1.x) allow remote attackers who have admin permissions to achieve remote code execution on a Bitbucket server instance via path traversal through the Data Center migration tool.
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HAtlassian Bitbucket
APPAtlassian5.13.0 – 5.13.6 (excl.)5.14.0 – 5.14.4 (excl.)5.15.0 – 5.15.3 (excl.)5.16.0 – 5.16.3 (excl.)6.0.0 – 6.0.3 (excl.)6.1.0 – 6.1.2 (excl.)
Related vulnerabilities
Command injection w Bitbucket Server i Data Center przez zmienne środowiskowe
Atlassian — pominięcie Servlet Filters umożliwia auth bypass i XSS
Command injection w Atlassian Bitbucket Server i Data Center via commit diff endpoint
RCE przez edycję dowiązań symbolicznych w Atlassian Bitbucket Server
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version...