CVE-2022-43781
Severity CVSS v4.0:
Pending analysis
Type:
CWE-77
Command Injection
Publication date:
17/11/2022
Last modified:
02/10/2024
Description
There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the Bitbucket Server and Data Center instance has enabled “Allow public signup”.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:* | 7.0.0 (including) | 7.6.19 (excluding) |
cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:* | 7.7.0 (including) | 7.17.12 (excluding) |
cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:* | 7.18.0 (including) | 7.21.6 (excluding) |
cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:* | 7.22.0 (including) | 8.0.5 (excluding) |
cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:* | 8.1.0 (including) | 8.1.5 (excluding) |
cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:* | 8.2.0 (including) | 8.2.4 (excluding) |
cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:* | 8.3.0 (including) | 8.3.3 (excluding) |
cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:* | 8.4.0 (including) | 8.4.2 (excluding) |
To consult the complete list of CPE names with products and versions, see this page