Junglewise Threat Intelligence

CVE-2022-36804: Atlassian Bitbucket Server and Data Center Command Injection Vulnerability

CVE-2022-36804 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-09-30

Technologies: Atlassian Data Center. Vendors: Atlassian.

Executive brief

Multiple API endpoints in Atlassian Bitbucket Server and Data Center contain a command injection vulnerability. An attacker with read permissions to a public or private repository can execute arbitrary code by sending a specially crafted HTTP request.

Affected products

  • Atlassian Bitbucket Server 7.0.0 to < 7.6.17, 7.7.0 to < 7.17.10, 7.18.0 to < 7.21.4, 8.0.0 to < 8.0.3, 8.1.0 to < 8.1.3, 8.2.0 to < 8.2.2, 8.3.0 to < 8.3.1
  • Atlassian Bitbucket Data Center 7.0.0 to < 7.6.17, 7.7.0 to < 7.17.10, 7.18.0 to < 7.21.4, 8.0.0 to < 8.0.3, 8.1.0 to < 8.1.3, 8.2.0 to < 8.2.2, 8.3.0 to < 8.3.1

Timeline

  • 2022-08-25: disclosed: NVD Published Date
  • 2022-09-30: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-09-30: exploited: Reported as exploited in the wild in advisory metadata

Related threats