Lucene search

K
prionPRIOn knowledge basePRION:CVE-2019-20097
HistoryJan 15, 2020 - 9:15 p.m.

Remote code execution

2020-01-1521:15:00
PRIOn knowledge base
www.prio-n.com
2

9.1 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

68.5%

Bitbucket Server and Bitbucket Data Center versions starting from 1.0.0 before 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.1.9, from version 6.2.0 before 6.2.7, from version 6.3.0 before 6.3.6, from version 6.4.0 before 6.4.4, from version 6.5.0 before 6.5.3, from version 6.6.0 before 6.6.3, from version 6.7.0 before 6.7.3, from version 6.8.0 before 6.8.2, from version 6.9.0 before 6.9.1 had a Remote Code Execution vulnerability via the post-receive hook. A remote attacker with permission to clone and push files to a repository on the victim’s Bitbucket Server or Bitbucket Data Center instance, can exploit this vulnerability to execute arbitrary commands on the Bitbucket Server or Bitbucket Data Center systems, using a file with specially crafted content.

9.1 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

68.5%

Related for PRION:CVE-2019-20097