CVE-2022-36804
Last modified
CVE-2022-36804 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21.4, from version 8.0.0 before version 8.0.3, from version 8.1.0 before version 8.1.3, and from version 8.2.0 before version 8.2.2, and from version 8.3.0 before 8.3.1 allows remote attackers with read permissions to a public or private Bitbucket repository to execute arbitrary code by sending a malicious HTTP request. This vulnerability was reported via our Bug Bounty Program by TheGrandPew.. CISA has confirmed active exploitation in the wild. EPSS estimates a 99.17% chance of exploitation in the next 30 days.
Description
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21.4, from version 8.0.0 before version 8.0.3, from version 8.1.0 before version 8.1.3, and from version 8.2.0 before version 8.2.2, and from version 8.3.0 before 8.3.1 allows remote attackers with read permissions to a public or private Bitbucket repository to execute arbitrary code by sending a malicious HTTP request. This vulnerability was reported via our Bug Bounty Program by TheGrandPew.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Atlassian | Bitbucket | >= 7.0.0, < 7.6.17 |
| Atlassian | Bitbucket | >= 7.7.0, < 7.17.10 |
| Atlassian | Bitbucket | >= 7.18.0, < 7.21.4 |
| Atlassian | Bitbucket | >= 8.0.0, < 8.0.3 |
| Atlassian | Bitbucket | >= 8.1.0, < 8.1.3 |
| Atlassian | Bitbucket | >= 8.2.0, < 8.2.2 |
| Atlassian | Bitbucket | 8.3.0 |
References
- http://packetstormsecurity.com/files/168470/Bitbucket-Git-Command-Injection.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/171453/Bitbucket-7.0.0-Remote-Command-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://jira.atlassian.com/browse/BSERV-13438Issue Tracking, Patch, Release Notes, Vendor Advisory
- http://packetstormsecurity.com/files/168470/Bitbucket-Git-Command-Injection.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/171453/Bitbucket-7.0.0-Remote-Command-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://jira.atlassian.com/browse/BSERV-13438Issue Tracking, Patch, Release Notes, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-36804US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2022-36804?
How severe is CVE-2022-36804?
How do I fix CVE-2022-36804?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-36799This issue exists to document that a security improvement in…7.2
- CVE-2022-3680Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2022-36800Affected versions of Atlassian Jira Service Management Serve…4.3
- CVE-2022-36801Affected versions of Atlassian Jira Server and Data Center a…6.1
- CVE-2022-36802The ManageJiraConnectors API in Atlassian Jira Align before …4.9
- CVE-2022-36803The MasterUserEdit API in Atlassian Jira Align Server before…8.8
- CVE-2022-3681A vulnerability has been identified in the MR2600 router v1.…6.5
- CVE-2022-36816Rejected reason: To maintain compliance with CNA rules, we h…
- CVE-2022-3682A vulnerability exists in the SDM600 file permission validat…8.8
- CVE-2022-36827Rejected reason: To maintain compliance with CNA rules, we h…
- CVE-2022-36829PendingIntent hijacking vulnerability in releaseAlarm in Cha…5.5
- CVE-2022-3683A vulnerability exists in the SDM600 API web services author…7.5
Are you affected by CVE-2022-36804?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
