Lucene search

K
atlassian[email protected]ATLASSIAN:BSERV-12753
HistoryFeb 16, 2021 - 12:44 a.m.

Privilege Escalation Vulnerability in Atlassian Bitbucket on Windows - CVE-2020-36233

2021-02-1600:44:08
jira.atlassian.com
64

0.0004 Low

EPSS

Percentile

0.4%

h3. Issue Summary

Atlassian Bitbucket on Windows fails to properly set ACLs on its installation directory. Because Bitbucket installs High-privileged services, this allows for multiple privilege escalation vulnerability possibilities.
h3. Affected Versions

The following versions are only affected on Windows:

  • All versions < 6.10.9
  • 7.x < 7.6.4
  • 7.7.x
  • 7.8.x
  • 7.9.x
  • 7.10.0

h3. Fixed Versions

  • 6.10.9 (Long Term Support release)
  • 7.6.4 (Long Term Support release)
  • 7.10.1

0.0004 Low

EPSS

Percentile

0.4%

Related for ATLASSIAN:BSERV-12753