QID 730926

Date Published: 2023-10-03

QID 730926: Atlassian Bitbucket Server and Data Center Remote Code Execution (RCE) Vulnerability (BSERV-14419)

There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to gain code execution and execute code on the system (CVE-2022-43781).

Affected Versions:
Atlassian Bitbucket Server and Data Center version from 8.0.0 before version 8.9.5
Atlassian Bitbucket Server and Data Center version from 8.10.0 before version 8.10.5
Atlassian Bitbucket Server and Data Center version from 8.11.0 before version 8.11.4
Atlassian Bitbucket Server and Data Center version from 8.12.0 before version 8.12.2
Atlassian Bitbucket Server and Data Center version from 8.13.0 before version 8.13.1

Detection Logic:
QID checks for vulnerable versions of Atlassian Bitbucket Server by sending a GET request to /login endpoint.

Successful exploitation of the vulnerability allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires no user interaction.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    Vendor has released fix for this vulnerability. Customers are advised to refer to Bitbucket Security Advisory for more information pertaining to this vulnerability.

    Vendor References

    CVEs related to QID 730926

    Software Advisories
    Advisory ID Software Component Link
    BSERV-14419 URL Logo jira.atlassian.com/browse/BSERV-14419