QID 730424
Date Published: 2022-04-07
QID 730424: Atlassian Bitbucket Data Center Remote Code Execution (RCE) Vulnerability
Bitbucket Data Center is a self-managed solution that provides source code collaboration for professional teams of any size, across any distance.
Bitbucket Data Center.
Affected Versions:
All 5.x versions >= 5.14.x
All 6.x versions
All 7.x versions less then 7.6.14
All versions 7.7.x through 7.16.x
7.17.x less then 7.17.6
7.18.x less then 7.18.4
7.19.x less then 7.19.4
7.20.0
QID Detection Logic(Unauthenticated):
It checks for vulnerable version of Atlassian Confluence using GET request to login.action page.
A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted JoinRequest, resulting in arbitrary code execution.
For more information please visit Bitbucket Data Center for remediation of this vulnerability.
Workaround:
Restrict access to the Hazelcast port by using a firewall or other network access controls. The port only needs to be accessible by other nodes in the Bitbucket.
For Bitbucket Data Center, Hazelcast uses TCP port 5701 by default.