CVE-2022-43781

There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the Bitbucket Server and Data Center instance has enabled “Allow public signup”.
References
Link Resource
https://confluence.atlassian.com/x/Y4hXRg Mitigation Release Notes
https://jira.atlassian.com/browse/BSERV-13522 Issue Tracking Patch
Configurations

Configuration 1

cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:*

Information

Published : 2022-11-17 12:15

Updated : 2022-11-18 06:51


NVD link : CVE-2022-43781

Mitre link : CVE-2022-43781

Products Affected
No products.
CWE