QID 150596

Date Published: 2022-11-28

QID 150596: Atlassian Bitbucket Server and Data Center: Command Injection Vulnerability (CVE-2022-43781)

Bitbucket is a Git-based source code repository hosting service owned by Atlassian.

In affected versions of Atlassian Bitbucket Server and Data Center a command injection vulnerability exists in environment variables where an attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the Bitbucket Server and Data Center instance has enabled "Allow public signup".

Affected versions :
Atlassian Bitbucket Server and Data Center version from 7.0.0 before version 7.6.19
Atlassian Bitbucket Server and Data Center version from 7.7.0 before version 7.17.12
Atlassian Bitbucket Server and Data Center version from 7.18.0 before version 7.21.6
Atlassian Bitbucket Server and Data Center version from 7.22.0 before version 8.0.5
Atlassian Bitbucket Server and Data Center version from 8.1.0 before version 8.1.5
Atlassian Bitbucket Server and Data Center version from 8.2.0 before version 8.2.4
Atlassian Bitbucket Server and Data Center version from 8.3.0 before version 8.3.3
Atlassian Bitbucket Server and Data Center version from 8.4.0 before version 8.4.2

QID Detection Logic:(Unauthenticated):
It checks for vulnerable version of Atlassian Bitbucket Server.

An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Vendor has released fix for this vulnerability. Customers are advised to refer to Bitbucket Security Advisory for more information pertaining to this vulnerability.

    CVEs related to QID 150596

    Software Advisories
    Advisory ID Software Component Link
    BSERV-13522 URL Logo jira.atlassian.com/browse/BSERV-13522
    Bitbucket Security Advisory URL Logo confluence.atlassian.com/bitbucketserver/bitbucket-server-and-data-center-security-advisory-2022-11-16-1180141667.html