← All CVEs

CVE-2022-43781

critical · 9.8

There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the Bitbucket Server and Data Center instance has enabled “Allow public signup”.

9.8
CVSS
98.1%
EPSS (exploit prob.)
100th
EPSS percentile
2022-11-17
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-77

Affected products

VendorProductAffected versions
atlassianbitbucket>= 7.0.0, < 7.6.19
atlassianbitbucket>= 7.7.0, < 7.17.12
atlassianbitbucket>= 7.18.0, < 7.21.6
atlassianbitbucket>= 7.22.0, < 8.0.5
atlassianbitbucket>= 8.1.0, < 8.1.5
atlassianbitbucket>= 8.2.0, < 8.2.4
atlassianbitbucket>= 8.3.0, < 8.3.3
atlassianbitbucket>= 8.4.0, < 8.4.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2022-43781