Loading HuntDB...

Bitbucket Server

76 Versions 18 CVEs

Versions

6.2.0

SEMANTIC 4 CVEs

>= 8.12.0

OTHER 1 CVE

6.0

MAJOR_MINOR 3 CVEs

7.20.0

SEMANTIC 2 CVEs

>= 8.1.0

OTHER 1 CVE

from 3.7.0 prior to 4.14.11

OTHER 1 CVE

from 5.1.0 prior to 5.1.8

OTHER 1 CVE

8.2.0

SEMANTIC 1 CVE

before 7.6.19

OTHER 1 CVE

>= 8.0.0

OTHER 1 CVE

8.1.0

SEMANTIC 3 CVEs

7.18.0

SEMANTIC 3 CVEs

from 5.0.0 prior to 5.0.9

OTHER 1 CVE

>= 8.14.0

OTHER 1 CVE

>= 8.12.2

OTHER 1 CVE

from 5.3.0 prior to 5.3.3

OTHER 1 CVE

>= 8.10.5

OTHER 1 CVE

5.8.0

SEMANTIC 1 CVE

5.6.0

SEMANTIC 1 CVE

before 8.3.3

OTHER 1 CVE

>= 8.3.0

OTHER 1 CVE

>= 8.7.0

OTHER 1 CVE

6.6.0

SEMANTIC 3 CVEs

before 7.0

OTHER 1 CVE

unspecified

OTHER 12 CVEs

>= 8.10.0

OTHER 1 CVE

>= 8.11.0

OTHER 1 CVE

>= 8.2.0

OTHER 1 CVE

>= 8.9.5

OTHER 1 CVE

6.1.0

SEMANTIC 4 CVEs

from 5.4.0 prior to 5.4.2

OTHER 1 CVE

before 8.4.2

OTHER 1 CVE

6.9.0

SEMANTIC 3 CVEs

>= 8.6.0

OTHER 1 CVE

>= 8.4.0

OTHER 1 CVE

6.3.0

SEMANTIC 4 CVEs

from 5.3.0 prior to 5.3.4

OTHER 1 CVE

7.0.0

SEMANTIC 2 CVEs

before 8.2.4

OTHER 1 CVE

7.21.0

SEMANTIC 2 CVEs

before 8.1.5

OTHER 1 CVE

1.0

MAJOR_MINOR 1 CVE

5.4.0

SEMANTIC 1 CVE

from 5.2.0 prior to 5.2.5

OTHER 1 CVE

6.8.0

SEMANTIC 3 CVEs

6.5.0

SEMANTIC 4 CVEs

5.7.0

SEMANTIC 1 CVE

from 5.2.0 prior to 5.2.6

OTHER 1 CVE

6.7.0

SEMANTIC 3 CVEs

from 5.4.0 prior to 5.4.1

OTHER 1 CVE

from 5.5.0 prior to 5.5.1

OTHER 1 CVE

>= 8.8.0

OTHER 1 CVE

5.5.0

SEMANTIC 1 CVE

8.3.0

SEMANTIC 1 CVE

>= 8.11.4

OTHER 1 CVE

< 8.0.0

OTHER 1 CVE

before 8.0.5

OTHER 1 CVE

4.13.0

SEMANTIC 1 CVE

3.0

MAJOR_MINOR 1 CVE

6.0.0

SEMANTIC 1 CVE

before 8.5.0

OTHER 1 CVE

4.9.0

SEMANTIC 1 CVE

before 7.21.6

OTHER 1 CVE

>= 8.13.1

OTHER 1 CVE

6.4.0

SEMANTIC 4 CVEs

>= 8.5.0

OTHER 1 CVE

prior to 5.6.0

OTHER 1 CVE

7.7.0

SEMANTIC 4 CVEs

>= 8.13.0

OTHER 1 CVE

prior to 5.3.0

OTHER 1 CVE

>= 8.9.0

OTHER 1 CVE

4.13

MAJOR_MINOR 1 CVE

7.16.0

SEMANTIC 2 CVEs

8.0.0

SEMANTIC 3 CVEs

from 5.1.0 prior to 5.1.7

OTHER 1 CVE

before 7.17.12

OTHER 1 CVE

Recent CVEs

CVE-2023-22513

This High severity RCE (Remote Code Execution) vulnerability was introduced in version 8.0.0 of Bitbucket Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.5, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires no user interaction. Atlassian recommends that Bitbucket Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Bitbucket Data Center and Server 8.9: Upgrade to a release greater than or equal to 8.9.5 Bitbucket Data Center and Server 8.10: Upgrade to a release greater than or equal to 8.10.5 Bitbucket Data Center and Server 8.11: Upgrade to a release greater than or equal to 8.11.4 Bitbucket Data Center and Server 8.12: Upgrade to a release greater than or equal to 8.12.2 Bitbucket Data Center and Server 8.13: Upgrade to a release greater than or equal to 8.13.1 Bitbucket Data Center and Server 8.14: Upgrade to a release greater than or equal to 8.14.0 Bitbucket Data Center and Server version >= 8.0 and < 8.9: Upgrade to any of the listed fix versions. See the release notes (https://confluence.atlassian.com/bitbucketserver/release-notes). You can download the latest version of Bitbucket Data Center and Server from the download center (https://www.atlassian.com/software/bitbucket/download-archives). This vulnerability was discovered by a private user and reported via our Bug Bounty program

HIGH Sep 19, 2023

CVE-2022-43781

There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the Bitbucket Server and Data Center instance has enabled “Allow public signup”.

UNKNOWN Nov 17, 2022

CVE-2020-36233

The Microsoft Windows Installer for Atlassian Bitbucket Server and Data Center before version 6.10.9, 7.x before 7.6.4, and from version 7.7.0 before 7.10.1 allows local attackers to escalate privileges because of weak permissions on the installation directory.

UNKNOWN Feb 18, 2021

CVE-2020-14170

Webhooks in Atlassian Bitbucket Server from version 5.4.0 before version 7.3.1 allow remote attackers to access the content of internal network resources via a Server-Side Request Forgery (SSRF) vulnerability.

UNKNOWN Jul 09, 2020

CVE-2019-20097

Bitbucket Server and Bitbucket Data Center versions starting from 1.0.0 before 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.1.9, from version 6.2.0 before 6.2.7, from version 6.3.0 before 6.3.6, from version 6.4.0 before 6.4.4, from version 6.5.0 before 6.5.3, from version 6.6.0 before 6.6.3, from version 6.7.0 before 6.7.3, from version 6.8.0 before 6.8.2, from version 6.9.0 before 6.9.1 had a Remote Code Execution vulnerability via the post-receive hook. A remote attacker with permission to clone and push files to a repository on the victim's Bitbucket Server or Bitbucket Data Center instance, can exploit this vulnerability to execute arbitrary commands on the Bitbucket Server or Bitbucket Data Center systems, using a file with specially crafted content.

UNKNOWN Jan 15, 2020

CVE-2019-15012

Bitbucket Server and Bitbucket Data Center from version 4.13. before 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.1.9, from version 6.2.0 before 6.2.7, from version 6.3.0 before 6.3.6, from version 6.4.0 before 6.4.4, from version 6.5.0 before 6.5.3, from version 6.6.0 before 6.6.3, from version 6.7.0 before 6.7.3, from version 6.8.0 before 6.8.2, from version 6.9.0 before 6.9.1 had a Remote Code Execution vulnerability via the edit-file request. A remote attacker with write permission on a repository can write to any arbitrary file to the victims Bitbucket Server or Bitbucket Data Center instance using the edit-file endpoint, if the user has Bitbucket Server or Bitbucket Data Center running, and has the permission to write the file at that destination. In some cases, this can result in execution of arbitrary code by the victims Bitbucket Server or Bitbucket Data Center instance.

UNKNOWN Jan 15, 2020

CVE-2019-15010

Bitbucket Server and Bitbucket Data Center versions starting from version 3.0.0 before version 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.1.9, from version 6.2.0 before 6.2.7, from version 6.3.0 before 6.3.6, from version 6.4.0 before 6.4.4, from version 6.5.0 before 6.5.3, from version 6.6.0 before 6.6.3, from version 6.7.0 before 6.7.3, from version 6.8.0 before 6.8.2, and from version 6.9.0 before 6.9.1 had a Remote Code Execution vulnerability via certain user input fields. A remote attacker with user level permissions can exploit this vulnerability to run arbitrary commands on the victim's systems. Using a specially crafted payload as user input, the attacker can execute arbitrary commands on the victim's Bitbucket Server or Bitbucket Data Center instance.

UNKNOWN Jan 15, 2020

CVE-2019-15005

The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message may contain configuration information about the application that the plugin is installed into. A vulnerable version of the plugin is included with Bitbucket Server / Data Center before 6.6.0, Confluence Server / Data Center before 7.0.1, Jira Server / Data Center before 8.3.2, Crowd / Crowd Data Center before 3.6.0, Fisheye before 4.7.2, Crucible before 4.7.2, and Bamboo before 6.10.2.

UNKNOWN Nov 08, 2019

CVE-2019-15000

The commit diff rest endpoint in Bitbucket Server and Data Center before 5.16.10 (the fixed version for 5.16.x ), from 6.0.0 before 6.0.10 (the fixed version for 6.0.x), from 6.1.0 before 6.1.8 (the fixed version for 6.1.x), from 6.2.0 before 6.2.6 (the fixed version for 6.2.x), from 6.3.0 before 6.3.5 (the fixed version for 6.3.x), from 6.4.0 before 6.4.3 (the fixed version for 6.4.x), and from 6.5.0 before 6.5.2 (the fixed version for 6.5.x) allows remote attackers who have permission to access a repository, if public access is enabled for a project or repository then attackers are able to exploit this issue anonymously, to read the contents of arbitrary files on the system and execute commands via injecting additional arguments into git commands.

UNKNOWN Sep 19, 2019

CVE-2018-5225

In browser editing in Atlassian Bitbucket Server from version 4.13.0 before 5.4.8 (the fixed version for 4.13.0 through 5.4.7), 5.5.0 before 5.5.8 (the fixed version for 5.5.x), 5.6.0 before 5.6.5 (the fixed version for 5.6.x), 5.7.0 before 5.7.3 (the fixed version for 5.7.x), and 5.8.0 before 5.8.2 (the fixed version for 5.8.x), allows authenticated users to gain remote code execution using the in browser editing feature via editing a symbolic link within a repository.

UNKNOWN Mar 22, 2018