← All CVEs

CVE-2022-36804

high · 8.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-09-30Remediation due 2022-10-21

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21.4, from version 8.0.0 before version 8.0.3, from version 8.1.0 before version 8.1.3, and from version 8.2.0 before version 8.2.2, and from version 8.3.0 before 8.3.1 allows remote attackers with read permissions to a public or private Bitbucket repository to execute arbitrary code by sending a malicious HTTP request. This vulnerability was reported via our Bug Bounty Program by TheGrandPew.

8.8
CVSS
99.2%
EPSS (exploit prob.)
100th
EPSS percentile
2022-08-25
Published

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-78CWE-88

Affected products

VendorProductAffected versions
atlassianbitbucket>= 7.0.0, < 7.6.17
atlassianbitbucket>= 7.7.0, < 7.17.10
atlassianbitbucket>= 7.18.0, < 7.21.4
atlassianbitbucket>= 8.0.0, < 8.0.3
atlassianbitbucket>= 8.1.0, < 8.1.3
atlassianbitbucket>= 8.2.0, < 8.2.2
atlassianbitbucket8.3.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2022-36804