PT-2021-11970 · Atlassian · Bitbucket+1

Will Dormann

·

Published

2021-02-18

·

Updated

2021-02-24

·

CVE-2020-36233

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Atlassian Bitbucket Server and Data Center versions prior to 6.10.9 Atlassian Bitbucket Server and Data Center versions 7.x prior to 7.6.4 Atlassian Bitbucket Server and Data Center versions 7.7.0 through 7.10.0
Description: The issue allows local attackers to escalate privileges due to weak permissions on the installation directory.
Recommendations: For versions prior to 6.10.9, update to version 6.10.9 or later. For versions 7.x prior to 7.6.4, update to version 7.6.4 or later. For versions 7.7.0 through 7.10.0, update to version 7.10.1 or later.

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-36233

Affected Products

Bitbucket
Bitbucket Server