CVE-2022-26133
critical · 9.8SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6, 7.18.0 and later prior to 7.18.4, 7.19.0 and later prior to 7.19.4, and 7.20.0 allow a remote, unauthenticated attacker to execute arbitrary code via Java deserialization.
9.8
CVSS
70.4%
EPSS (exploit prob.)
99th
EPSS percentile
2022-04-20
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-502
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| atlassian | bitbucket_data_center | >= 5.14.0, < 7.6.14 |
| atlassian | bitbucket_data_center | >= 7.7.0, < 7.17.6 |
| atlassian | bitbucket_data_center | >= 7.18.0, < 7.18.4 |
| atlassian | bitbucket_data_center | >= 7.19.0, < 7.19.4 |
| atlassian | bitbucket_data_center | 7.20.0 |
Check a specific version with /api/v1/cve/match.
References
- https://confluence.atlassian.com/security/multiple-products-security-advisory-hazelcast-vulnerable-to-remote-code-execution-cve-2016-10750-1116292387.html
- https://jira.atlassian.com/browse/BSERV-13173
- https://confluence.atlassian.com/security/multiple-products-security-advisory-hazelcast-vulnerable-to-remote-code-execution-cve-2016-10750-1116292387.html
- https://jira.atlassian.com/browse/BSERV-13173
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2022-26133