Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-3397


Atlassian Bitbucket Data Center licensed instances starting with version 5.13.0 before 5.13.6 (the fixed version for 5.13.x), from 5.14.0 before 5.14.4 (fixed version for 5.14.x), from 5.15.0 before 5.15.3 (fixed version for 5.15.x), from 5.16.0 before 5.16.3 (fixed version for 5.16.x), from 6.0.0 before 6.0.3 (fixed version for 6.0.x), and from 6.1.0 before 6.1.2 (the fixed version for 6.1.x) allow remote attackers who have admin permissions to achieve remote code execution on a Bitbucket server instance via path traversal through the Data Center migration tool.


Published

2019-06-03T14:29:00.293

Last Modified

2024-11-21T04:42:01.703

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 9.1 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

8.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application atlassian bitbucket < 5.13.6 Yes
Application atlassian bitbucket < 5.14.4 Yes
Application atlassian bitbucket < 5.15.3 Yes
Application atlassian bitbucket < 5.16.3 Yes
Application atlassian bitbucket < 6.0.3 Yes
Application atlassian bitbucket < 6.1.2 Yes

References