Loading HuntDB...

Bitbucket Data Center

73 Versions 13 CVEs

Versions

6.2.0

SEMANTIC 4 CVEs

8.19.1

SEMANTIC 1 CVE

>= 8.12.0

OTHER 1 CVE

6.0

MAJOR_MINOR 3 CVEs

7.20.0

SEMANTIC 3 CVEs

>= 8.1.0

OTHER 1 CVE

8.2.0

SEMANTIC 1 CVE

before 7.6.19

OTHER 1 CVE

8.1.0

SEMANTIC 3 CVEs

>= 8.0.0

OTHER 1 CVE

8.9.13 to 8.9.17

OTHER 1 CVE

7.18.0

SEMANTIC 4 CVEs

>= 8.14.0

OTHER 1 CVE

8.8.0 to 8.8.7

OTHER 1 CVE

>= 8.12.2

OTHER 1 CVE

8.6.0 to 8.6.4

OTHER 1 CVE

>= 8.10.5

OTHER 1 CVE

8.3.0 to 8.3.4

OTHER 1 CVE

6.6.0

SEMANTIC 3 CVEs

before 8.3.3

OTHER 1 CVE

>= 8.7.0

OTHER 1 CVE

>= 8.3.0

OTHER 1 CVE

before 7.0

OTHER 1 CVE

unspecified

OTHER 10 CVEs

>= 8.10.0

OTHER 1 CVE

8.2.2 to 8.2.4

OTHER 1 CVE

>= 8.11.0

OTHER 1 CVE

>= 8.2.0

OTHER 1 CVE

>= 8.9.5

OTHER 1 CVE

6.1.0

SEMANTIC 5 CVEs

before 8.4.2

OTHER 1 CVE

8.5.0 to 8.5.4

OTHER 1 CVE

6.9.0

SEMANTIC 3 CVEs

>= 8.6.0

OTHER 1 CVE

>= 8.4.0

OTHER 1 CVE

6.3.0

SEMANTIC 4 CVEs

8.4.0 to 8.4.4

OTHER 1 CVE

7.19.0

SEMANTIC 1 CVE

5.14.0

SEMANTIC 2 CVEs

7.0.0

SEMANTIC 2 CVEs

5.15.0

SEMANTIC 1 CVE

before 8.2.4

OTHER 1 CVE

7.21.0

SEMANTIC 2 CVEs

before 8.1.5

OTHER 1 CVE

8.19.2 to 8.19.6

OTHER 1 CVE

1.0

MAJOR_MINOR 1 CVE

8.9.0 to 8.9.12

OTHER 1 CVE

6.8.0

SEMANTIC 3 CVEs

6.5.0

SEMANTIC 4 CVEs

5.13.0

SEMANTIC 1 CVE

6.7.0

SEMANTIC 3 CVEs

8.7.0 to 8.7.5

OTHER 1 CVE

>= 8.8.0

OTHER 1 CVE

8.3.0

SEMANTIC 1 CVE

>= 8.11.4

OTHER 1 CVE

< 8.0.0

OTHER 1 CVE

before 8.0.5

OTHER 1 CVE

3.0

MAJOR_MINOR 1 CVE

6.0.0

SEMANTIC 2 CVEs

before 8.5.0

OTHER 1 CVE

8.1.3 to 8.1.5

OTHER 1 CVE

before 7.21.6

OTHER 1 CVE

>= 8.13.1

OTHER 1 CVE

6.4.0

SEMANTIC 4 CVEs

>= 8.5.0

OTHER 1 CVE

7.7.0

SEMANTIC 5 CVEs

>= 8.13.0

OTHER 1 CVE

4.13

MAJOR_MINOR 1 CVE

>= 8.9.0

OTHER 1 CVE

7.16.0

SEMANTIC 2 CVEs

8.0.3 to 8.0.5

OTHER 1 CVE

8.0.0

SEMANTIC 3 CVEs

before 7.17.12

OTHER 1 CVE

Recent CVEs

CVE-2024-21684

There is a low severity open redirect vulnerability within affected versions of Bitbucket Data Center. Versions of Bitbucket DC from 8.0.0 to 8.9.12 and 8.19.0 to 8.19.1 are affected by this vulnerability. It is patched in 8.9.13 and 8.19.2. This open redirect vulnerability, with a CVSS Score of 3.1 and a CVSS Vector of CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N, allows an unauthenticated attacker to redirect a victim user upon login to Bitbucket Data Center to any arbitrary site which can be utilized for further exploitation which has low impact to confidentiality, no impact to integrity, no impact to availability, and requires user interaction. Atlassian recommends that Bitbucket Data Center customers upgrade to the version. If you are unable to do so, upgrade your instance to one of the supported fixed versions.

LOW Jul 24, 2024

CVE-2023-22513

This High severity RCE (Remote Code Execution) vulnerability was introduced in version 8.0.0 of Bitbucket Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.5, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires no user interaction. Atlassian recommends that Bitbucket Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Bitbucket Data Center and Server 8.9: Upgrade to a release greater than or equal to 8.9.5 Bitbucket Data Center and Server 8.10: Upgrade to a release greater than or equal to 8.10.5 Bitbucket Data Center and Server 8.11: Upgrade to a release greater than or equal to 8.11.4 Bitbucket Data Center and Server 8.12: Upgrade to a release greater than or equal to 8.12.2 Bitbucket Data Center and Server 8.13: Upgrade to a release greater than or equal to 8.13.1 Bitbucket Data Center and Server 8.14: Upgrade to a release greater than or equal to 8.14.0 Bitbucket Data Center and Server version >= 8.0 and < 8.9: Upgrade to any of the listed fix versions. See the release notes (https://confluence.atlassian.com/bitbucketserver/release-notes). You can download the latest version of Bitbucket Data Center and Server from the download center (https://www.atlassian.com/software/bitbucket/download-archives). This vulnerability was discovered by a private user and reported via our Bug Bounty program

HIGH Sep 19, 2023

CVE-2022-43781

There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the Bitbucket Server and Data Center instance has enabled “Allow public signup”.

UNKNOWN Nov 17, 2022

CVE-2022-26136

A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulnerability can result in authentication bypass and cross-site scripting. Atlassian has released updates that fix the root cause of this vulnerability, but has not exhaustively enumerated all potential consequences of this vulnerability. Atlassian Bamboo versions are affected before 8.0.9, from 8.1.0 before 8.1.8, and from 8.2.0 before 8.2.4. Atlassian Bitbucket versions are affected before 7.6.16, from 7.7.0 before 7.17.8, from 7.18.0 before 7.19.5, from 7.20.0 before 7.20.2, from 7.21.0 before 7.21.2, and versions 8.0.0 and 8.1.0. Atlassian Confluence versions are affected before 7.4.17, from 7.5.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and version 7.21.0. Atlassian Crowd versions are affected before 4.3.8, from 4.4.0 before 4.4.2, and version 5.0.0. Atlassian Fisheye and Crucible versions before 4.8.10 are affected. Atlassian Jira versions are affected before 8.13.22, from 8.14.0 before 8.20.10, and from 8.21.0 before 8.22.4. Atlassian Jira Service Management versions are affected before 4.13.22, from 4.14.0 before 4.20.10, and from 4.21.0 before 4.22.4.

UNKNOWN Jul 20, 2022

CVE-2020-36233

The Microsoft Windows Installer for Atlassian Bitbucket Server and Data Center before version 6.10.9, 7.x before 7.6.4, and from version 7.7.0 before 7.10.1 allows local attackers to escalate privileges because of weak permissions on the installation directory.

UNKNOWN Feb 18, 2021

CVE-2019-20097

Bitbucket Server and Bitbucket Data Center versions starting from 1.0.0 before 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.1.9, from version 6.2.0 before 6.2.7, from version 6.3.0 before 6.3.6, from version 6.4.0 before 6.4.4, from version 6.5.0 before 6.5.3, from version 6.6.0 before 6.6.3, from version 6.7.0 before 6.7.3, from version 6.8.0 before 6.8.2, from version 6.9.0 before 6.9.1 had a Remote Code Execution vulnerability via the post-receive hook. A remote attacker with permission to clone and push files to a repository on the victim's Bitbucket Server or Bitbucket Data Center instance, can exploit this vulnerability to execute arbitrary commands on the Bitbucket Server or Bitbucket Data Center systems, using a file with specially crafted content.

UNKNOWN Jan 15, 2020

CVE-2019-15012

Bitbucket Server and Bitbucket Data Center from version 4.13. before 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.1.9, from version 6.2.0 before 6.2.7, from version 6.3.0 before 6.3.6, from version 6.4.0 before 6.4.4, from version 6.5.0 before 6.5.3, from version 6.6.0 before 6.6.3, from version 6.7.0 before 6.7.3, from version 6.8.0 before 6.8.2, from version 6.9.0 before 6.9.1 had a Remote Code Execution vulnerability via the edit-file request. A remote attacker with write permission on a repository can write to any arbitrary file to the victims Bitbucket Server or Bitbucket Data Center instance using the edit-file endpoint, if the user has Bitbucket Server or Bitbucket Data Center running, and has the permission to write the file at that destination. In some cases, this can result in execution of arbitrary code by the victims Bitbucket Server or Bitbucket Data Center instance.

UNKNOWN Jan 15, 2020

CVE-2019-15010

Bitbucket Server and Bitbucket Data Center versions starting from version 3.0.0 before version 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.1.9, from version 6.2.0 before 6.2.7, from version 6.3.0 before 6.3.6, from version 6.4.0 before 6.4.4, from version 6.5.0 before 6.5.3, from version 6.6.0 before 6.6.3, from version 6.7.0 before 6.7.3, from version 6.8.0 before 6.8.2, and from version 6.9.0 before 6.9.1 had a Remote Code Execution vulnerability via certain user input fields. A remote attacker with user level permissions can exploit this vulnerability to run arbitrary commands on the victim's systems. Using a specially crafted payload as user input, the attacker can execute arbitrary commands on the victim's Bitbucket Server or Bitbucket Data Center instance.

UNKNOWN Jan 15, 2020

CVE-2019-15000

The commit diff rest endpoint in Bitbucket Server and Data Center before 5.16.10 (the fixed version for 5.16.x ), from 6.0.0 before 6.0.10 (the fixed version for 6.0.x), from 6.1.0 before 6.1.8 (the fixed version for 6.1.x), from 6.2.0 before 6.2.6 (the fixed version for 6.2.x), from 6.3.0 before 6.3.5 (the fixed version for 6.3.x), from 6.4.0 before 6.4.3 (the fixed version for 6.4.x), and from 6.5.0 before 6.5.2 (the fixed version for 6.5.x) allows remote attackers who have permission to access a repository, if public access is enabled for a project or repository then attackers are able to exploit this issue anonymously, to read the contents of arbitrary files on the system and execute commands via injecting additional arguments into git commands.

UNKNOWN Sep 19, 2019

CVE-2019-3397

Atlassian Bitbucket Data Center licensed instances starting with version 5.13.0 before 5.13.6 (the fixed version for 5.13.x), from 5.14.0 before 5.14.4 (fixed version for 5.14.x), from 5.15.0 before 5.15.3 (fixed version for 5.15.x), from 5.16.0 before 5.16.3 (fixed version for 5.16.x), from 6.0.0 before 6.0.3 (fixed version for 6.0.x), and from 6.1.0 before 6.1.2 (the fixed version for 6.1.x) allow remote attackers who have admin permissions to achieve remote code execution on a Bitbucket server instance via path traversal through the Data Center migration tool.

UNKNOWN Jun 03, 2019