About CVE-2022-36804

Vulnerability Name Atlassian Bitbucket Command Injection Vulnerability (CVE-2022-36804)
Attack Type Command Injection
Time Discovered 2022-08-24
Updated Time 2022-08-29
CVE ID CVE-2022-36804

Summary

Recently, the Sangfor security team has detected a piece of information about a command injection vulnerability in Bitbucket Server and Bitbucket Data Center components.With access to public Bitbucket repositories or read access to private repositories, an attacker can execute arbitrary code by sending malicious HTTP requests and ultimately gain server access.

Affected Versions

7.0.0 ≤ Atlassian Bitbucket Server ≤ 8.3.0
7.0.0 ≤ Atlassian Bitbucket Data Center ≤ 8.3.0

Solution

The latest official version has been released, and affected users are advised to update and upgrade to the latest version in time. The link is as follows: https://confluence.atlassian.com/bitbucketserver/bitbucket-server-and-data-center-advisory-2022-08-24-1155489835.html

Related Links

https://jira.atlassian.com/browse/BSERV-13438

Listen To This Post

Search

Get in Touch

Get in Touch with Sangfor Team for Business Inquiry

Name
Email Address
Business Phone Number
Tell us about your project requirements

Related Articles

Roundup of Microsoft Patch Tuesday (June 2025)

Date : 13 Jun 2025
Read Now

CVE-2025-27817: Apache Kafka Connect Arbitrary File Read

Date : 12 Jun 2025
Read Now

CVE-2025-5419: Out-of-Bounds Read/Write Vulnerability in V8 in Google Chrome

Date : 03 Jun 2025
Read Now

See Other Product

Athena SASE - Secure Access Service Edge
Sangfor Athena NGFW - Next Generation Firewall
Sangfor Athena EPP - Modern Endpoint Protection Platform
Sangfor Athena NDR - Network Detection and Response
Cyber Command - NDR Platform
Managed Detection Response (MDR) Total Cost of Ownership (TCO) Calculator