There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the Bitbucket Server and Data Center instance has enabled “Allow public signup”.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAtlassian Bitbucket
APPAtlassian7.0.0 – 7.6.19 (excl.)7.7.0 – 7.17.12 (excl.)7.18.0 – 7.21.6 (excl.)7.22.0 – 8.0.5 (excl.)8.1.0 – 8.1.5 (excl.)8.2.0 – 8.2.4 (excl.)8.3.0 – 8.3.3 (excl.)8.4.0 – 8.4.2 (excl.)
Related vulnerabilities
Atlassian — pominięcie Servlet Filters umożliwia auth bypass i XSS
Command injection w Atlassian Bitbucket Server i Data Center via commit diff endpoint
RCE przez path traversal w narzędziu migracji Atlassian Bitbucket Data Center
RCE przez edycję dowiązań symbolicznych w Atlassian Bitbucket Server
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version...