EXPOSURES › CVE-2022-36804
CVE-2022-36804
HIGH ⌖ ON CISA KEV · EXPLOITEDBitbucket Server and Data Center exposed to command injection attacks via multiple API endpoints
An attacker with access to a Bitbucket repository could execute arbitrary code via a malicious HTTP request, highlighting a severe security flaw in Atlassian's product that was actively exploited in the wild.
Shame score — Active exploitation in the wild and lack of patching indicates negligence and a severe breach of trust for DIB organizations relying on Atlassian's services.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Multiple API endpoints of Atlassian Bitbucket Server and Data Center contain a command injection vulnerability where an attacker with access to a public Bitbucket repository, or with read permissions to a private one, can execute code by sending a malicious HTTP request.