Lucene search

K
atlassianSecurity-metrics-botBSERV-13438
HistoryAug 17, 2022 - 10:40 p.m.

Critical severity command injection vulnerability - CVE-2022-36804

2022-08-1722:40:01
security-metrics-bot
jira.atlassian.com
109
command injection
bitbucket server
bitbucket data center
cve-2022-36804
arbitrary code execution
http request
security advisory
bug bounty program

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.974 High

EPSS

Percentile

99.9%

h3. Command injection vulnerability through malicious HTTP requests

There is a command injection vulnerability in multiple API endpoints of Bitbucket Server and Data Center. An attacker with access to a public Bitbucket repository or with read permissions to a private one can execute arbitrary code by sending a malicious HTTP request.

All versions released after 6.10.17 including 7.0.0 and newer are affected, this means that all instances that are running any versions between 7.0.0 and 8.3.0 inclusive can be exploited by this vulnerability.

The full list of affected versions can be found in the “Affects Version/s:” field of this report.
h4. Affected versions:

All Bitbucket Server and Data Center versions from 7.0.0 to 8.3.0 inclusive.
h4. Fixed versions:
||Supported Version||Bug Fix Release||
|[Bitbucket Server and Data Center 7.6|https://confluence.atlassian.com/display/BitbucketServer/Bitbucket+Server+7.6+release+notes]|7.6.17 ([LTS|https://confluence.atlassian.com/enterprise/long-term-support-releases-948227420.html]) or newer|
|[Bitbucket Server and Data Center 7.17|https://confluence.atlassian.com/display/BitbucketServer/Bitbucket+Data+Center+and+Server+7.17+release+notes]|7.17.10 ([LTS|https://confluence.atlassian.com/enterprise/long-term-support-releases-948227420.html]) or newer|
|[Bitbucket Server and Data Center 7.21|https://confluence.atlassian.com/display/BitbucketServer/Bitbucket+Data+Center+and+Server+7.21+release+notes]|7.21.4 ([LTS|https://confluence.atlassian.com/enterprise/long-term-support-releases-948227420.html]) or newer|
|[Bitbucket Server and Data Center 8.0|https://confluence.atlassian.com/display/BitbucketServer/Bitbucket+Data+Center+and+Server+8.0+release+notes]|8.0.3 or newer|
|[Bitbucket Server and Data Center 8.1|https://confluence.atlassian.com/display/BitbucketServer/Bitbucket+Data+Center+and+Server+8.1+release+notes]|8.1.3 or newer|
|[Bitbucket Server and Data Center 8.2|https://confluence.atlassian.com/display/BitbucketServer/Bitbucket+Data+Center+and+Server+8.2+release+notes]|8.2.2 or newer|
|[Bitbucket Server and Data Center 8.3|https://confluence.atlassian.com/display/BitbucketServer/Bitbucket+Data+Center+and+Server+8.3+release+notes]|8.3.1 or newer|
h4. Bitbucket Mesh

If you have configured Bitbucket Mesh nodes, these will need to be updated with to the corresponding version of Mesh that includes the fix. To find the version of Mesh compatible with the Bitbucket Data Center version, please check the [+compatibility matrix+|https://confluence.atlassian.com/display/BitbucketServer/Bitbucket+Mesh+compatibility+matrix]. You can download the corresponding version from the [download centre|https://www.atlassian.com/software/bitbucket/download-mesh-archives].

For additional details, please see full advisory here: [https://confluence.atlassian.com/pages/viewpage.action?spaceKey=SECURITY&title=August+2022%3A+Atlassian+Security+Advisories+Overview]

This vulnerability was discovered by [@TheGrandPew|https://twitter.com/TheGrandPew] and reported via our Bug Bounty program.

Affected configurations

Vulners
Node
atlassianbitbucket_data_centerRange7.0.0
OR
atlassianbitbucket_data_centerRange7.0.1
OR
atlassianbitbucket_data_centerRange7.2.0
OR
atlassianbitbucket_data_centerRange7.0.2
OR
atlassianbitbucket_data_centerRange7.1.1
OR
atlassianbitbucket_data_centerRange7.0.3
OR
atlassianbitbucket_data_centerRange7.1.2
OR
atlassianbitbucket_data_centerRange7.0.4
OR
atlassianbitbucket_data_centerRange7.1.3
OR
atlassianbitbucket_data_centerRange7.2.1
OR
atlassianbitbucket_data_centerRange7.3.0
OR
atlassianbitbucket_data_centerRange7.0.5
OR
atlassianbitbucket_data_centerRange7.1.4
OR
atlassianbitbucket_data_centerRange7.2.2
OR
atlassianbitbucket_data_centerRange7.2.3
OR
atlassianbitbucket_data_centerRange7.2.4
OR
atlassianbitbucket_data_centerRange7.4.0
OR
atlassianbitbucket_data_centerRange7.3.1
OR
atlassianbitbucket_data_centerRange7.2.5
OR
atlassianbitbucket_data_centerRange7.3.2
OR
atlassianbitbucket_data_centerRange7.4.1
OR
atlassianbitbucket_data_centerRange7.5.0
OR
atlassianbitbucket_data_centerRange7.4.2
OR
atlassianbitbucket_data_centerRange7.5.1
OR
atlassianbitbucket_data_centerRange7.6.0
OR
atlassianbitbucket_data_centerRange7.2.6
OR
atlassianbitbucket_data_centerRange7.5.2
OR
atlassianbitbucket_data_centerRange7.6.1
OR
atlassianbitbucket_data_centerRange7.7.0
OR
atlassianbitbucket_data_centerRange7.8.0
OR
atlassianbitbucket_data_centerRange7.7.1
OR
atlassianbitbucket_data_centerRange7.6.2
OR
atlassianbitbucket_data_centerRange7.9.0
OR
atlassianbitbucket_data_centerRange7.8.1
OR
atlassianbitbucket_data_centerRange7.9.1
OR
atlassianbitbucket_data_centerRange7.10.0
OR
atlassianbitbucket_data_centerRange7.6.3
OR
atlassianbitbucket_data_centerRange7.6.4
OR
atlassianbitbucket_data_centerRange7.10.1
OR
atlassianbitbucket_data_centerRange7.12.0
OR
atlassianbitbucket_data_centerRange7.11.1
OR
atlassianbitbucket_data_centerRange7.6.5
OR
atlassianbitbucket_data_centerRange7.11.2
OR
atlassianbitbucket_data_centerRange7.6.6
OR
atlassianbitbucket_data_centerRange7.13.0
OR
atlassianbitbucket_data_centerRange7.12.1
OR
atlassianbitbucket_data_centerRange7.6.7
OR
atlassianbitbucket_data_centerRange7.14.0
OR
atlassianbitbucket_data_centerRange7.13.1
OR
atlassianbitbucket_data_centerRange7.15.0
OR
atlassianbitbucket_data_centerRange7.14.1
OR
atlassianbitbucket_data_centerRange7.6.8
OR
atlassianbitbucket_data_centerRange7.14.2
OR
atlassianbitbucket_data_centerRange7.6.9
OR
atlassianbitbucket_data_centerRange7.15.1
OR
atlassianbitbucket_data_centerRange7.16.0
OR
atlassianbitbucket_data_centerRange7.15.2
OR
atlassianbitbucket_data_centerRange7.17.0
OR
atlassianbitbucket_data_centerRange7.18.0
OR
atlassianbitbucket_data_centerRange7.16.1
OR
atlassianbitbucket_data_centerRange7.6.10
OR
atlassianbitbucket_data_centerRange7.17.1
OR
atlassianbitbucket_data_centerRange7.17.2
OR
atlassianbitbucket_data_centerRange7.18.1
OR
atlassianbitbucket_data_centerRange7.6.11
OR
atlassianbitbucket_data_centerRange7.16.2
OR
atlassianbitbucket_data_centerRange7.17.3
OR
atlassianbitbucket_data_centerRange7.18.2
OR
atlassianbitbucket_data_centerRange7.20.0
OR
atlassianbitbucket_data_centerRange7.18.3
OR
atlassianbitbucket_data_centerRange7.17.4
OR
atlassianbitbucket_data_centerRange7.15.3
OR
atlassianbitbucket_data_centerRange7.16.3
OR
atlassianbitbucket_data_centerRange7.6.12
OR
atlassianbitbucket_data_centerRange7.6.13
OR
atlassianbitbucket_data_centerRange7.19.2
OR
atlassianbitbucket_data_centerRange7.18.4
OR
atlassianbitbucket_data_centerRange7.17.5
OR
atlassianbitbucket_data_centerRange7.19.3
OR
atlassianbitbucket_data_centerRange7.6.14
OR
atlassianbitbucket_data_centerRange8.0.0
OR
atlassianbitbucket_data_centerRange7.17.6
OR
atlassianbitbucket_data_centerRange7.19.4
OR
atlassianbitbucket_data_centerRange7.20.1
OR
atlassianbitbucket_data_centerRange7.19.5
OR
atlassianbitbucket_data_centerRange7.20.2
OR
atlassianbitbucket_data_centerRange8.1.0
OR
atlassianbitbucket_data_centerRange8.2.0
OR
atlassianbitbucket_data_centerRange8.0.1
OR
atlassianbitbucket_data_centerRange8.1.1
OR
atlassianbitbucket_data_centerRange7.20.3
OR
atlassianbitbucket_data_centerRange8.0.2
OR
atlassianbitbucket_data_centerRange8.1.2
OR
atlassianbitbucket_data_centerRange8.2.1
OR
atlassianbitbucket_data_centerRange8.3.0
OR
atlassianbitbucket_data_centerRange7.6.15
OR
atlassianbitbucket_data_centerRange7.6.16
OR
atlassianbitbucket_data_centerRange7.17.7
OR
atlassianbitbucket_data_centerRange7.17.8
OR
atlassianbitbucket_data_centerRange7.17.9
OR
atlassianbitbucket_data_centerRange7.21.0
OR
atlassianbitbucket_data_centerRange7.21.1
OR
atlassianbitbucket_data_centerRange7.21.2
OR
atlassianbitbucket_data_centerRange7.21.3
OR
atlassianbitbucket_data_centerRange<8.0.3
OR
atlassianbitbucket_data_centerRange<8.1.3
OR
atlassianbitbucket_data_centerRange<8.2.2
OR
atlassianbitbucket_data_centerRange<8.3.1
OR
atlassianbitbucket_data_centerRange<7.6.17
OR
atlassianbitbucket_data_centerRange<7.17.10
OR
atlassianbitbucket_data_centerRange<7.21.4

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.974 High

EPSS

Percentile

99.9%