ZeroHour

CVE-2022-36804

KEV PoC ×2large

Command Injection RCE in Atlassian Bitbucket Server and Data Center

CISA: Atlassian Bitbucket Server and Data Center Command Injection Vulnerability

CVSS 3.1
8.8 high
EPSS
99%p100
Published
()
KEV added
AI analysis

Multiple API endpoints in Atlassian Bitbucket Server and Data Center contain an OS command injection flaw (CWE-78, with argument injection CWE-88) that allows a remote attacker to run arbitrary commands on the server. It is triggered by sending a malicious HTTP request to an affected API endpoint and requires only read permission to any public or private Bitbucket repository, meaning most authenticated users — and users of public repositories — can trigger it. Successful exploitation yields arbitrary code execution on the Bitbucket host, exposing source code and potentially the wider system. All Bitbucket Server and Data Center releases from 7.0.0 through the listed pre-fix versions are affected, with fixes in 7.6.17, 7.17.10, 7.21.4, 8.0.3, 8.1.3, 8.2.2, and 8.3.1. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-09-30, public PoC exploits exist, and EPSS assigns a ~99.2% probability of exploitation within 30 days.

What to do: Immediately upgrade Bitbucket Server/Data Center per vendor instructions to 7.6.17+, 7.17.10+, 7.21.4+, 8.0.3+, 8.1.3+, 8.2.2+, or 8.3.1+ depending on your release branch — this is a CISA KEV-listed, actively exploited vulnerability. Until patched, restrict internet-facing access to Bitbucket instances and review HTTP access and audit logs for suspicious requests to REST API endpoints, which would indicate attempted or successful exploitation.

Affected
Atlassian Bitbucket Server and Data Center7.0.0 up to but not including 7.6.17
Atlassian Bitbucket Server and Data Center7.7.0 up to but not including 7.17.10
Atlassian Bitbucket Server and Data Center7.18.0 up to but not including 7.21.4
Atlassian Bitbucket Server and Data Center8.0.0 up to but not including 8.0.3
Atlassian Bitbucket Server and Data Center8.1.0 up to but not including 8.1.3
Atlassian Bitbucket Server and Data Center8.2.0 up to but not including 8.2.2
Atlassian Bitbucket Server and Data Center8.3.0 up to but not including 8.3.1
Estimated exposure
largetens of thousands of internet-exposed Bitbucket Server/Data Center instances, with a substantially larger total installed base on internal networks — Bitbucket Server and Data Center is a widely deployed self-hosted enterprise Git platform, and public internet scan counts around the time of disclosure found tens of thousands of Bitbucket instances reachable online, while many more…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21.4, from version 8.0.0 before version 8.0.3, from version 8.1.0 before version 8.1.3, and from version 8.2.0 before version 8.2.2, and from version 8.3.0 before 8.3.1 allows remote attackers with read permissions to a public or private Bitbucket repository to execute arbitrary code by sending a malicious HTTP request. This vulnerability was reported via our Bug Bounty Program by TheGrandPew.

CISA Known Exploited Vulnerability
Affected
Atlassian Bitbucket Server and Data Center
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
atlassian
Products
bitbucket
Weakness
CWE-78, CWE-88
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news