PT-2022-6078 · Atlassian+6 · Bitbucket+8

Jonathan Leitschuh

·

Published

2022-04-11

·

Updated

2026-05-18

·

CVE-2022-1471

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SnakeYaml versions prior to 2.0 Bitbucket Data Center versions 7.17.x through 8.8.6 Bitbucket Server versions 7.17.x through 8.8.6 Confluence Data Center versions 6.13.x through 8.3.0 Confluence Server versions 6.13.x through 8.3.0
Description The SnakeYaml library's Constructor class does not restrict types that can be instantiated during deserialization, allowing an attacker to execute remote code by providing malicious YAML content. This issue affects multiple Atlassian products, including Bitbucket Data Center, Bitbucket Server, Confluence Data Center, and Confluence Server. Atlassian Cloud sites are not affected. The vulnerability can be exploited by deserializing YAML content provided by an attacker, leading to remote code execution.
Recommendations For SnakeYaml, upgrade to version 2.0 or beyond. For Bitbucket Data Center and Bitbucket Server, patch to version 7.21.16 (LTS), 8.8.7, 8.9.4 (LTS), 8.10.4, 8.11.3, 8.12.1, or later. For Confluence Data Center and Confluence Server, patch to version 7.19.17 (LTS), 8.4.5, 8.5.4 (LTS), 8.6.2 (Data Center Only), or 8.7.1 (Data Center Only). As a temporary workaround, consider using SnakeYaml's SafeConstructor when parsing untrusted content to restrict deserialization.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:9058
ALSA-2022_9058
ALSA-2025_16880
BDU:2023-00013
CESA-2022_9058
CLEANSTART-2026-CI66802
CLEANSTART-2026-GH89210
CLEANSTART-2026-KU61465
CLEANSTART-2026-LE11246
CLEANSTART-2026-RN56220
CVE-2022-1471
ELSA-2022-9058-1
GHSA-MJMJ-J48Q-9WG2
OPENSUSE-SU-2024:13151-1
RHSA-2022:9058
RHSA-2022_9058
RHSA-2023:0697
RHSA-2023:0777
RHSA-2023:1043
RHSA-2023:1044
RHSA-2023:1045
RHSA-2023:1512
RHSA-2023:1513
RHSA-2023:1514
RHSA-2023:2097
RHSA-2023:3198
RHSA-2023:6171
RHSA-2024:0775
RHSA-2025:1746
RHSA-2025:1747
RLSA-2022:9058
RLSA-2022_9058
RLSA-2023:2097
RLSA-2023_2097

Affected Products

Almalinux
Bitbucket
Bitbucket Server
Centos
Confluence
Debian
Red Hat
Red Os
Rocky Linux