Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-43781
HistoryNov 17, 2022 - 12:15 a.m.

Command injection

2022-11-1700:15:00
PRIOn knowledge base
www.prio-n.com
29
command injection
bitbucket server
data center
environment variables
arbitrary code
unauthenticated
public signup

9.8 High

AI Score

Confidence

High

0.57 Medium

EPSS

Percentile

97.7%

There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the Bitbucket Server and Data Center instance has enabled β€œAllow public signup”.

9.8 High

AI Score

Confidence

High

0.57 Medium

EPSS

Percentile

97.7%