QID 150596
Date Published: 2022-11-28
QID 150596: Atlassian Bitbucket Server and Data Center: Command Injection Vulnerability (CVE-2022-43781)
Bitbucket is a Git-based source code repository hosting service owned by Atlassian.
In affected versions of Atlassian Bitbucket Server and Data Center a command injection vulnerability exists in environment variables where an attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the Bitbucket Server and Data Center instance has enabled "Allow public signup".
Affected versions :
Atlassian Bitbucket Server and Data Center version from 7.0.0 before version 7.6.19
Atlassian Bitbucket Server and Data Center version from 7.7.0 before version 7.17.12
Atlassian Bitbucket Server and Data Center version from 7.18.0 before version 7.21.6
Atlassian Bitbucket Server and Data Center version from 7.22.0 before version 8.0.5
Atlassian Bitbucket Server and Data Center version from 8.1.0 before version 8.1.5
Atlassian Bitbucket Server and Data Center version from 8.2.0 before version 8.2.4
Atlassian Bitbucket Server and Data Center version from 8.3.0 before version 8.3.3
Atlassian Bitbucket Server and Data Center version from 8.4.0 before version 8.4.2
QID Detection Logic:(Unauthenticated):
It checks for vulnerable version of Atlassian Bitbucket Server.
An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system.
- BSERV-13522 -
jira.atlassian.com/browse/BSERV-13522 - Bitbucket Security Advisory -
confluence.atlassian.com/bitbucketserver/bitbucket-server-and-data-center-security-advisory-2022-11-16-1180141667.html
CVEs related to QID 150596
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| BSERV-13522 |
|
||
| Bitbucket Security Advisory |
|