CVE-2022-43781

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
17/11/2022
Last modified:
02/10/2024

Description

There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the Bitbucket Server and Data Center instance has enabled “Allow public signup”.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:* 7.0.0 (including) 7.6.19 (excluding)
cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:* 7.7.0 (including) 7.17.12 (excluding)
cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:* 7.18.0 (including) 7.21.6 (excluding)
cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:* 7.22.0 (including) 8.0.5 (excluding)
cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:* 8.1.0 (including) 8.1.5 (excluding)
cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:* 8.2.0 (including) 8.2.4 (excluding)
cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:* 8.3.0 (including) 8.3.3 (excluding)
cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:* 8.4.0 (including) 8.4.2 (excluding)