Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21.4, from version 8.0.0 before version 8.0.3, from version 8.1.0 before version 8.1.3, and from version 8.2.0 before version 8.2.2, and from version 8.3.0 before 8.3.1 allows remote attackers with read permissions to a public or private Bitbucket repository to execute arbitrary code by sending a malicious HTTP request. This vulnerability was reported via our Bug Bounty Program by TheGrandPew.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HAtlassian Bitbucket
APPAtlassian8.3.07.7.0 – 7.17.10 (excl.)7.18.0 – 7.21.4 (excl.)7.0.0 – 7.6.17 (excl.)8.1.0 – 8.1.3 (excl.)8.2.0 – 8.2.2 (excl.)8.0.0 – 8.0.3 (excl.)
CISA KEV — detailsi
- Vendori
- Atlassian ↗
- Producti
- Bitbucket Server and Data Center
- Added to KEVi
- September 30, 2022
- Remediation deadline (US Federal)i
- October 21, 2022(overdue)
Apply updates per vendor instructions.
Multiple API endpoints of Atlassian Bitbucket Server and Data Center contain a command injection vulnerability where an attacker with access to a public Bitbucket repository, or with read permissions to a private one, can execute code by sending a malicious HTTP request.
Related vulnerabilities
Command injection w Bitbucket Server i Data Center przez zmienne środowiskowe
Atlassian — pominięcie Servlet Filters umożliwia auth bypass i XSS
Command injection w Atlassian Bitbucket Server i Data Center via commit diff endpoint
RCE przez path traversal w narzędziu migracji Atlassian Bitbucket Data Center
RCE przez edycję dowiązań symbolicznych w Atlassian Bitbucket Server