CVE-2022-36804
KEV PoC ×2largeCommand Injection RCE in Atlassian Bitbucket Server and Data Center
CISA: Atlassian Bitbucket Server and Data Center Command Injection Vulnerability
Multiple API endpoints in Atlassian Bitbucket Server and Data Center contain an OS command injection flaw (CWE-78, with argument injection CWE-88) that allows a remote attacker to run arbitrary commands on the server. It is triggered by sending a malicious HTTP request to an affected API endpoint and requires only read permission to any public or private Bitbucket repository, meaning most authenticated users — and users of public repositories — can trigger it. Successful exploitation yields arbitrary code execution on the Bitbucket host, exposing source code and potentially the wider system. All Bitbucket Server and Data Center releases from 7.0.0 through the listed pre-fix versions are affected, with fixes in 7.6.17, 7.17.10, 7.21.4, 8.0.3, 8.1.3, 8.2.2, and 8.3.1. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-09-30, public PoC exploits exist, and EPSS assigns a ~99.2% probability of exploitation within 30 days.
What to do: Immediately upgrade Bitbucket Server/Data Center per vendor instructions to 7.6.17+, 7.17.10+, 7.21.4+, 8.0.3+, 8.1.3+, 8.2.2+, or 8.3.1+ depending on your release branch — this is a CISA KEV-listed, actively exploited vulnerability. Until patched, restrict internet-facing access to Bitbucket instances and review HTTP access and audit logs for suspicious requests to REST API endpoints, which would indicate attempted or successful exploitation.
| Atlassian Bitbucket Server and Data Center | 7.0.0 up to but not including 7.6.17 |
| Atlassian Bitbucket Server and Data Center | 7.7.0 up to but not including 7.17.10 |
| Atlassian Bitbucket Server and Data Center | 7.18.0 up to but not including 7.21.4 |
| Atlassian Bitbucket Server and Data Center | 8.0.0 up to but not including 8.0.3 |
| Atlassian Bitbucket Server and Data Center | 8.1.0 up to but not including 8.1.3 |
| Atlassian Bitbucket Server and Data Center | 8.2.0 up to but not including 8.2.2 |
| Atlassian Bitbucket Server and Data Center | 8.3.0 up to but not including 8.3.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21.4, from version 8.0.0 before version 8.0.3, from version 8.1.0 before version 8.1.3, and from version 8.2.0 before version 8.2.2, and from version 8.3.0 before 8.3.1 allows remote attackers with read permissions to a public or private Bitbucket repository to execute arbitrary code by sending a malicious HTTP request. This vulnerability was reported via our Bug Bounty Program by TheGrandPew.
- Affected
- Atlassian Bitbucket Server and Data Center
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- atlassian
- Products
- bitbucket
- Weakness
- CWE-78, CWE-88
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H