Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-43781


There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the Bitbucket Server and Data Center instance has enabled “Allow public signup”.


Published

2022-11-17T00:15:18.483

Last Modified

2024-11-21T07:27:14.543

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-77
  • Type: Secondary
    CWE-77

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application atlassian bitbucket < 7.6.19 Yes
Application atlassian bitbucket < 7.17.12 Yes
Application atlassian bitbucket < 7.21.6 Yes
Application atlassian bitbucket < 8.0.5 Yes
Application atlassian bitbucket < 8.1.5 Yes
Application atlassian bitbucket < 8.2.4 Yes
Application atlassian bitbucket < 8.3.3 Yes
Application atlassian bitbucket < 8.4.2 Yes

References