CVE-2022-43781
Last modified
CVE-2022-43781 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. EPSS estimates a 98.04% chance of exploitation in the next 30 days.
Description
There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the Bitbucket Server and Data Center instance has enabled “Allow public signup”.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Atlassian | Bitbucket | >= 7.0.0, < 7.6.19 |
| Atlassian | Bitbucket | >= 7.7.0, < 7.17.12 |
| Atlassian | Bitbucket | >= 7.18.0, < 7.21.6 |
| Atlassian | Bitbucket | >= 7.22.0, < 8.0.5 |
| Atlassian | Bitbucket | >= 8.1.0, < 8.1.5 |
| Atlassian | Bitbucket | >= 8.2.0, < 8.2.4 |
| Atlassian | Bitbucket | >= 8.3.0, < 8.3.3 |
| Atlassian | Bitbucket | >= 8.4.0, < 8.4.2 |
References
- https://confluence.atlassian.com/x/Y4hXRgMitigation, Release Notes, Vendor Advisory
- https://jira.atlassian.com/browse/BSERV-13522Issue Tracking, Patch, Vendor Advisory
- https://confluence.atlassian.com/x/Y4hXRgMitigation, Release Notes, Vendor Advisory
- https://jira.atlassian.com/browse/BSERV-13522Issue Tracking, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-43781?
How severe is CVE-2022-43781?
How do I fix CVE-2022-43781?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-43776The url parameter of the /api/geojson endpoint in Metabase v…6.5
- CVE-2022-43777Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilit…7.8
- CVE-2022-43778Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilit…7.8
- CVE-2022-43779A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerabil…7
- CVE-2022-4378A stack overflow flaw was found in the Linux kernel's SYSCTL…7.8
- CVE-2022-43780Certain HP ENVY, OfficeJet, and DeskJet printers may be vuln…7.5
- CVE-2022-43782Affected versions of Atlassian Crowd allow an attacker to au…9.8
- CVE-2022-43783Rejected reason: To maintain compliance with CNA rules, we h…
- CVE-2022-43784Rejected reason: To maintain compliance with CNA rules, we h…
- CVE-2022-43785Rejected reason: To maintain compliance with CNA rules, we h…
- CVE-2022-43786Rejected reason: To maintain compliance with CNA rules, we h…
- CVE-2022-43787Rejected reason: To maintain compliance with CNA rules, we h…
Are you affected by CVE-2022-43781?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
