PT-2022-5667 · Atlassian · Bitbucket+1

Ry0Tak

·

Published

2022-10-12

·

Updated

2024-10-02

·

CVE-2022-43781

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Atlassian Bitbucket Server and Data Center (affected versions not specified)
Description The issue is related to a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the Bitbucket Server and Data Center instance has enabled “Allow public signup”. The problem is caused by the possibility of command injection through environment variables.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-07062
CVE-2022-43781

Affected Products

Bitbucket
Bitbucket Server