QID 379557
QID 379557: Atlassian Bitbucket Data Center and Server hutool-json Dependency Vulnerability (BSERV-18789)
Bitbucket Data Center looks like a single instance of Bitbucket Server to users, but under the hood, it consists of a cluster of multiple machines ("cluster nodes") each running the Bitbucket Server web application, behind a load balancer.
CVE-2022-45688: A stack overflow in the XML.toJSONObject component of hutool-json allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data.
Affected version:
7.21.x: prior to 7.21.16
7.17.0 to 7.17.21
8.7.0 to 8.7.5
8.8.0 to 8.8.7
8.9.x: prior to 8.9.4
8.10.x: prior to 8.10.4
8.11.x: prior to 8.11.3
8.12.x: prior to 8.12.1
QID Detection Logic(Unauthenticated):
The QID checks for vulnerable versions of Atlassian Bitbucket Server by sending a GET request to /login endpoint.
QID Detection Logic:(Authenticated)
The QID checks for vulnerable versions of Atlassian Bitbucket Server by checking the registry entry for windows and invoking commands in linux.
Note: Here, we are not checking actual version of hutool-json Third-Party Dependency. Hence, QID set as practice.
Successful exploitation of this vulnerability allows Denial of Service (DoS).
- BSERV-18789 -
jira.atlassian.com/browse/BSERV-18789
CVEs related to QID 379557
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| BSERV-18789 |
|