About CVE-2022-36804

Vulnerability Name Atlassian Bitbucket Command Injection Vulnerability (CVE-2022-36804)
Attack Type Command Injection
Time Discovered 2022-08-24
Updated Time 2022-08-29
CVE ID CVE-2022-36804

Summary

Recently, the Sangfor security team has detected a piece of information about a command injection vulnerability in Bitbucket Server and Bitbucket Data Center components.With access to public Bitbucket repositories or read access to private repositories, an attacker can execute arbitrary code by sending malicious HTTP requests and ultimately gain server access.

Affected Versions

7.0.0 ≤ Atlassian Bitbucket Server ≤ 8.3.0
7.0.0 ≤ Atlassian Bitbucket Data Center ≤ 8.3.0

Solution

The latest official version has been released, and affected users are advised to update and upgrade to the latest version in time. The link is as follows: https://confluence.atlassian.com/bitbucketserver/bitbucket-server-and-data-center-advisory-2022-08-24-1155489835.html

Related Links

https://jira.atlassian.com/browse/BSERV-13438

Listen To This Post

Search

Get in Touch

Get in Touch with Sangfor Team for Business Inquiry

Related Articles

CVE-2024-47575: Fortinet FortiManager Authentication Vulnerability

Date : 25 Oct 2024
Read Now

CVE-2024-38819: Path Traversal Vulnerability

Date : 19 Oct 2024
Read Now

CVE-2024-40766: SonicWALL SonicOS Access Control Flaw Vulnerability

Date : 12 Sep 2024
Read Now

See Other Product

Sangfor Omni-Command
Replace your Enterprise NGAV with Sangfor Endpoint Secure
Cyber Command - NDR Platform
Endpoint Secure
Internet Access Gateway (IAG)
Sangfor Network Secure - Next Generation Firewall