Skip to content
COOEY

EXPOSURES › CVE-2022-36804

CVE-2022-36804

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-09-30 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-36804 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 90/100 rceexploited-in-wildunpatched

Bitbucket Server and Data Center exposed to command injection attacks via multiple API endpoints

An attacker with access to a Bitbucket repository could execute arbitrary code via a malicious HTTP request, highlighting a severe security flaw in Atlassian's product that was actively exploited in the wild.

Shame score — Active exploitation in the wild and lack of patching indicates negligence and a severe breach of trust for DIB organizations relying on Atlassian's services.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Multiple API endpoints of Atlassian Bitbucket Server and Data Center contain a command injection vulnerability where an attacker with access to a public Bitbucket repository, or with read permissions to a private one, can execute code by sending a malicious HTTP request.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.