Loading HuntDB...

GHSA-3883-h64p-r3xm

GitHub Security Advisory

⚠ Unreviewed CRITICAL Has CVE

Advisory Details

There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the Bitbucket Server and Data Center instance has enabled “Allow public signup”.

Related CVEs

Key Information

GHSA ID
GHSA-3883-h64p-r3xm
Published
July 6, 2023 7:24 PM
Last Modified
October 2, 2024 6:31 PM
CVSS Score
9.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: November 25, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.