QID 379558
QID 379558: Atlassian Bitbucket Data Center and Server org.apache.tomcat.embed:tomcat-embed-core Dependency Vulnerability (BSERV-19097)
Bitbucket Data Center looks like a single instance of Bitbucket Server to users, but under the hood, it consists of a cluster of multiple machines ("cluster nodes") each running the Bitbucket Server web application, behind a load balancer.
CVE-2022-45688: org.apache.tomcat.embed:tomcat-embed-core Dependency vulnerability
Affected version:
7.21.x: prior to 7.21.21
8.9.x: prior to 8.9.9
8.11.0 to 8.11.6
8.12.0 to 8.12.6
8.13.x: prior to 8.13.5
8.14.x: prior to 8.14.4
8.15.x: prior to 8.15.3
8.16.x: prior to 8.16.2
QID Detection Logic(Unauthenticated):
The QID checks for vulnerable versions of Atlassian Bitbucket Server by sending a GET request to /login endpoint.
QID Detection Logic:(Authenticated)
The QID checks for vulnerable versions of Atlassian Bitbucket Server by checking the registry entry for windows and invoking commands in linux.
Note: Here, we are not checking actual version of org.apache.tomcat.embed:tomcat-embed-core Dependency. Hence, QID set as practice.
Successful exploitation of this vulnerability an unauthenticated attacker to expose assets in your environment.
- BSERV-19097 -
jira.atlassian.com/browse/BSERV-19097
CVEs related to QID 379558
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| BSERV-19097 |
|