QID 730309

QID 730309: Atlassian Bitbucket Privilege Escalation Vulnerability (CVE-2020-36233)

The Microsoft Windows Installer for Atlassian Bitbucket Server allows local attackers to escalate privileges because of weak permissions on the installation directory.

Affected Bitbucket Versions:
all versions before 6.10.9,
7.x before 7.6.4, and
from version 7.7.0 before 7.10.1

Note: Only Windows installer of Atlassian Bitbucket is affected.

Detection Logic:(Unauthenticated)
This QID checks for the vulnerable versions of Bitbucket via a GET login request.

Successful exploitation of this vulnerability allows local attackers to escalate privileges because of weak permissions on the installation directory.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    Workaround:
    Vendor has released fix to this issue. Refer to Atlassian Bitbucket
    Vendor References

    CVEs related to QID 730309

    Software Advisories
    Advisory ID Software Component Link
    BSERV-12753 URL Logo jira.atlassian.com/browse/BSERV-12753