About CVE-2022-36804
Vulnerability Name | Atlassian Bitbucket Command Injection Vulnerability (CVE-2022-36804) |
---|---|
Attack Type | Command Injection |
Time Discovered | 2022-08-24 |
Updated Time | 2022-08-29 |
CVE ID | CVE-2022-36804 |
Summary
Recently, the Sangfor security team has detected a piece of information about a command injection vulnerability in Bitbucket Server and Bitbucket Data Center components.With access to public Bitbucket repositories or read access to private repositories, an attacker can execute arbitrary code by sending malicious HTTP requests and ultimately gain server access.
Affected Versions
7.0.0 ≤ Atlassian Bitbucket Server ≤ 8.3.0
7.0.0 ≤ Atlassian Bitbucket Data Center ≤ 8.3.0
Solution
The latest official version has been released, and affected users are advised to update and upgrade to the latest version in time. The link is as follows: https://confluence.atlassian.com/bitbucketserver/bitbucket-server-and-data-center-advisory-2022-08-24-1155489835.html