Executive brief
Multiple API endpoints in Atlassian Bitbucket Server and Data Center contain a command injection vulnerability. An attacker with read permissions to a public or private repository can execute arbitrary code by sending a specially crafted HTTP request.
Affected products
- Atlassian Bitbucket Server 7.0.0 to < 7.6.17, 7.7.0 to < 7.17.10, 7.18.0 to < 7.21.4, 8.0.0 to < 8.0.3, 8.1.0 to < 8.1.3, 8.2.0 to < 8.2.2, 8.3.0 to < 8.3.1
- Atlassian Bitbucket Data Center 7.0.0 to < 7.6.17, 7.7.0 to < 7.17.10, 7.18.0 to < 7.21.4, 8.0.0 to < 8.0.3, 8.1.0 to < 8.1.3, 8.2.0 to < 8.2.2, 8.3.0 to < 8.3.1
Timeline
- 2022-08-25: disclosed: NVD Published Date
- 2022-09-30: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-09-30: exploited: Reported as exploited in the wild in advisory metadata