QID 730926
Date Published: 2023-10-03
QID 730926: Atlassian Bitbucket Server and Data Center Remote Code Execution (RCE) Vulnerability (BSERV-14419)
There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to gain code execution and execute code on the system (CVE-2022-43781).
Affected Versions:
Atlassian Bitbucket Server and Data Center version from 8.0.0 before version 8.9.5
Atlassian Bitbucket Server and Data Center version from 8.10.0 before version 8.10.5
Atlassian Bitbucket Server and Data Center version from 8.11.0 before version 8.11.4
Atlassian Bitbucket Server and Data Center version from 8.12.0 before version 8.12.2
Atlassian Bitbucket Server and Data Center version from 8.13.0 before version 8.13.1
Detection Logic:
QID checks for vulnerable versions of Atlassian Bitbucket Server by sending a GET request to /login endpoint.
Successful exploitation of the vulnerability allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires no user interaction.
- BSERV-14419 -
jira.atlassian.com/browse/BSERV-14419
CVEs related to QID 730926
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| BSERV-14419 |
|