Loading HuntDB...

Atlassian Bitbucket Server and Data Center Command Injection Vulnerability

Added Sept. 30, 2022 Due Oct. 21, 2022 CVE-2022-36804
Overdue Atlassian / Bitbucket Server and Data Center CWE-78 CWE-88 CWE-158

Description

Multiple API endpoints of Atlassian Bitbucket Server and Data Center contain a command injection vulnerability where an attacker with access to a public Bitbucket repository, or with read permissions to a private one, can execute code by sending a malicious HTTP request.

Required Action

Apply updates per vendor instructions.

References

Additional Information

Catalog Version
2025.01.24
Catalog Released
Jan. 24, 2025
Days Until Due
0 days
Last Updated
6 months ago