Lucene search

K
hiveproHiveForce LabHIVEPRO:8F5F41019F148247B2BACDBF6A02070C
HistoryNov 23, 2022 - 12:13 p.m.

Atlassian Addresses Issues in Crowd and Bitbucket Products

2022-11-2312:13:27
HiveForce Lab
www.hivepro.com
15
atlassian
security holes
arbitrary code execution
intruder
ip address
password validation
user management
rest api
command injection
bitbucket server
data center
environment variables
code execution.

0.57 Medium

EPSS

Percentile

97.7%

Threat Level Vulnerability Report For a detailed threat advisory, download the pdf file here Summary Atlassian has two security holes that can be abused to allow arbitrary code execution. CVE-2022-43782 allows an intruder connecting from an IP address on the allow list to authenticate as the crowd application by evading the password validation. The attacker may then exploit the user-management path to access privileged endpoints in Crowd's REST API. The command injection vulnerability (CVE-2022-43781) in Bitbucket Server and Data Center is exploited by using environment variables in the software. An attacker with access to credentials can leverage this flaw to achieve code execution and execute code on the system.

0.57 Medium

EPSS

Percentile

97.7%