Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-26133


SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6, 7.18.0 and later prior to 7.18.4, 7.19.0 and later prior to 7.19.4, and 7.20.0 allow a remote, unauthenticated attacker to execute arbitrary code via Java deserialization.


Published

2022-04-20T19:15:08.157

Last Modified

2024-11-21T06:53:29.743

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-502
  • Type: Secondary
    CWE-502

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application atlassian bitbucket_data_center < 7.6.14 Yes
Application atlassian bitbucket_data_center < 7.17.6 Yes
Application atlassian bitbucket_data_center < 7.18.4 Yes
Application atlassian bitbucket_data_center < 7.19.4 Yes
Application atlassian bitbucket_data_center 7.20.0 Yes

References