HIGH

CVE-2022-36804

Atlassian Bitbucket 2022-08-25 CVSS v3.1
CVSS
8.8
KEV

Description

Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21.4, from version 8.0.0 before version 8.0.3, from version 8.1.0 before version 8.1.3, and from version 8.2.0 before version 8.2.2, and from version 8.3.0 before 8.3.1 allows remote attackers with read permissions to a public or private Bitbucket repository to execute arbitrary code by sending a malicious HTTP request. This vulnerability was reported via our Bug Bounty Program by TheGrandPew.

Summary dbcve.org

A command injection vulnerability in multiple API endpoints of Atlassian Bitbucket Server and Data Center allows remote attackers with repository read permissions to execute arbitrary code via malicious HTTP requests. The vulnerability affects specific version ranges (7.0.0-7.6.16, 7.7.0-7.17.9, 7.18.0-7.21.3, 8.0.0-8.0.2, 8.1.0-8.1.2, 8.2.0-8.2.1, 8.3.0) and is patched in versions 7.6.17, 7.17.10, 7.21.4, 8.0.3, 8.1.3, 8.2.2, and 8.3.1.

Mitigation

Upgrade Bitbucket Server or Data Center to one of the patched versions (7.6.17, 7.17.10, 7.21.4, 8.0.3, 8.1.3, 8.2.2, or 8.3.1). In the interim, restrict network access to Bitbucket and limit repository read permissions to trusted users only.

Proof of Concept
Patch Commit

Weakness (CWE)

CWE-78 OS Command Injection
CWE-88

EPSS Score

99.17%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE