CVE-2022-43781
Published on: Not Yet Published
Last Modified on: 11/18/2022 06:51:00 PM UTC
Certain versions of Bitbucket from Atlassian contain the following vulnerability:
There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the Bitbucket Server and Data Center instance has enabled “Allow public signup”.
- CVE-2022-43781 has been assigned by
[email protected] to track the vulnerability - currently rated as CRITICAL severity.
CVSS3 Score: 9.8 - CRITICAL
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Bitbucket Server and Data Center Security Advisory 2022-11-16 | Bitbucket Data Center and Server 8.6 | Atlassian Documentation | confluence.atlassian.com text/html |
![]() |
[BSERV-13522] Critical severity command injection vulnerability - CVE-2022-43781 - Create and track feature requests for Atlassian products. | jira.atlassian.com text/html |
![]() |
Related QID Numbers
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Atlassian | Bitbucket | All | All | All | All |
- cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-43781 : There is a command injection vulnerability using environment variables in Bitbucket Server and Dat… twitter.com/i/web/status/1… | 2022-11-17 00:04:53 |
![]() |
Potentially Critical CVE Detected! CVE-2022-43781 There is a command injection vulnerability using environment vari… twitter.com/i/web/status/1… | 2022-11-17 00:55:55 |
![]() |
CVE-2022-43781 | 2022-11-17 00:38:47 |
![]() |
Atlassian Releases Patches for Critical Flaws Affecting Crowd and Bitbucket Products | 2022-11-21 08:05:41 |