ZeroHour

CVE-2022-43781

CVSS 3.1
9.8 critical
EPSS
98%p100
Published
()
Modified
Description

There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the Bitbucket Server and Data Center instance has enabled “Allow public signup”.

Vendors
atlassian
Products
bitbucket
Weakness
CWE-77
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news