QID 376867

Date Published: 2022-08-30

QID 376867: Atlassian Bitbucket Data Center Remote Code Execution (RCE) Vulnerability (BSERV-13173) (Authenticated Check)

Bitbucket Data Center is a self-managed solution that provides source code collaboration for professional teams of any size, across any distance.

CVE-2022-26133: Allow a remote unauthenticated attacker to execute arbitrary code via Java deserialization.

Affected Versions:
Bitbucket Data Center versions from 5.14.x prior to 7.6.14
Bitbucket Data Center versions from 7.7.x prior to 7.16.x
Bitbucket Data Center versions from 7.17.x prior to 7.17.6
Bitbucket Data Center versions from 7.18.x prior to 7.18.4
Bitbucket Data Center versions from 7.19.x prior to 7.19.4
Bitbucket Data Center version 7.20.0

NOTE:
Bitbucket Server is not affected.
Bitbucket Cloud is not affected.
QID Detection Logic(Authenticated):
It checks for vulnerable version of Atlassian Bitbucket running on the target.

Successful exploitation of this vulnerability may allow an unauthenticated remote attacker to execute arbitrary code on the target system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    The vendor has released multiple patch versions: 7.6.14, 7.17.6, 7.18.4, 7.19.4, 7.20.1, 7.21.0
    For more information please visit Bitbucket Data Center for remediation of this vulnerability.

    Vendor References

    CVEs related to QID 376867

    Software Advisories
    Advisory ID Software Component Link
    BSERV-13173 URL Logo jira.atlassian.com/browse/BSERV-13173