CISA Warns of Hackers Exploiting Critical Atlassian Bitbucket Server Vulnerability
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-36804 | Command Injection RCE in Atlassian Bitbucket Server and Data Center Multiple API endpoints in Atlassian Bitbucket Server and Data Center contain an OS command injection flaw (CWE-78, with argument injection CWE-88) that allows a remote attacker to run arbitrary commands on the server. It is triggered by sending a malicious HTTP request to an affected API endpoint and requires only read permission to any public or private Bitbucket repository, meaning most authenticated users — and users of public repositories — can trigger it. Successful exploitation yields arbitrary code execution on the Bitbucket host, exposing source code and potentially the wider system. All Bitbucket Server and Data Center releases from 7.0.0 through the listed pre-fix versions are affected, with fixes in 7.6.17, 7.17.10, 7.21.4, 8.0.3, 8.1.3, 8.2.2, and 8.3.1. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-09-30, public PoC exploits exist, and EPSS assigns a ~99.2% probability of exploitation within 30 days. Do: Immediately upgrade Bitbucket Server/Data Center per vendor instructions to 7.6.17+, 7.17.10+, 7.21.4+, 8.0.3+, 8.1.3+, 8.2.2+, or 8.3.1+ depending on your release branch — this is a CISA KEV-listed, actively exploited vulnerability. Until patched, restrict internet-facing access to Bitbucket instances and review HTTP access and audit logs for suspicious requests to REST API endpoints, which would indicate attempted or successful exploitation. | 8.8 | 99% | KEV PoC ×2 |
| largetens of thousands of internet-exposed Bitbucket Server/Data Center instances, with a substantially larger total installed base on internal networks |
Full article224 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananOct 01, 2022
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a recently disclosed critical flaw impacting Atlassian's Bitbucket Server and Data Center to the Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
Tracked as CVE-2022-36804, the issue relates to a command injection vulnerability that could allow malicious actors to gain arbitrary code execution on susceptible installations by sending a specially crafted HTTP request.
Successful exploitation, however, banks on the prerequisite that the attacker already has access to a public repository or possesses read permissions to a private Bitbucket repository.
"All versions of Bitbucket Server and Datacenter released after 6.10.17 including 7.0.0 and newer are affected, this means that all instances that are running any versions between 7.0.0 and 8.3.0 inclusive are affected by this vulnerability," Atlassian noted in a late August 2022 advisory.
CISA did not provide further details about how the flaw is being exploited and how widespread exploitation efforts are, but GreyNoise said it detected evidence of in-the-wild abuse on September 20 and 23.
As countermeasures, all Federal Civilian Executive Branch (FCEB) agencies are required to remediate the vulnerabilities by October 21, 2022 to protect networks against active threats.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/10/cisa-warns-of-hackers-exploiting.html