Atlassian Releases Patches for Critical Flaws Affecting Crowd and Bitbucket Products
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-36804 | Command Injection RCE in Atlassian Bitbucket Server and Data Center Multiple API endpoints in Atlassian Bitbucket Server and Data Center contain an OS command injection flaw (CWE-78, with argument injection CWE-88) that allows a remote attacker to run arbitrary commands on the server. It is triggered by sending a malicious HTTP request to an affected API endpoint and requires only read permission to any public or private Bitbucket repository, meaning most authenticated users — and users of public repositories — can trigger it. Successful exploitation yields arbitrary code execution on the Bitbucket host, exposing source code and potentially the wider system. All Bitbucket Server and Data Center releases from 7.0.0 through the listed pre-fix versions are affected, with fixes in 7.6.17, 7.17.10, 7.21.4, 8.0.3, 8.1.3, 8.2.2, and 8.3.1. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-09-30, public PoC exploits exist, and EPSS assigns a ~99.2% probability of exploitation within 30 days. Do: Immediately upgrade Bitbucket Server/Data Center per vendor instructions to 7.6.17+, 7.17.10+, 7.21.4+, 8.0.3+, 8.1.3+, 8.2.2+, or 8.3.1+ depending on your release branch — this is a CISA KEV-listed, actively exploited vulnerability. Until patched, restrict internet-facing access to Bitbucket instances and review HTTP access and audit logs for suspicious requests to REST API endpoints, which would indicate attempted or successful exploitation. | 8.8 | 99% | KEV PoC ×2 |
| largetens of thousands of internet-exposed Bitbucket Server/Data Center instances, with a substantially larger total installed base on internal networks | |
| CVE-2022-43781 | There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the Bitbucket Server and Data Center instance has enabled “Allow public signup”. NVD description · AI analysis pending | 9.8 | 98% |
| — | ||
| CVE-2022-43782 | Affected versions of Atlassian Crowd allow an attacker to authenticate as the crowd application via security misconfiguration and subsequent ability to call pri Affected versions of Atlassian Crowd allow an attacker to authenticate as the crowd application via security misconfiguration and subsequent ability to call privileged endpoints in Crowd's REST API under the {{usermanagement}} path. This vulnerability can only be exploited by IPs specified under the crowd application allowlist in the Remote Addresses configuration, which is {{none}} by default. The affected versions are all versions 3.x.x, versions 4.x.x before version 4.4.4, and versions 5.x.x before 5.0.3 NVD description · AI analysis pending | 9.8 | <1% |
| — |
Full article341 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananNov 19, 2022
Australian software company Atlassian has rolled out security updates to address two critical flaws affecting Bitbucket Server, Data Center, and Crowd products.
The issues, tracked as CVE-2022-43781 and CVE-2022-43782, are both rated 9 out of 10 on the CVSS vulnerability scoring system.
CVE-2022-43781, which Atlassian said was introduced in version 7.0.0 of Bitbucket Server and Data Center, affects versions 7.0 to 7.21 and 8.0 to 8.4 (only if mesh.enabled is set to false in bitbucket.properties).
The weakness has been described as a case of command injection using environment variables in the software, which could allow an adversary with permission to control their username to gain code execution on the affected system.
As a temporary workaround, the company is recommending users turn off the "Public Signup" option (Administration > Authentication).
"Disabling public signup would change the attack vector from an unauthenticated attack to an authenticated one which would reduce the risk of exploitation," it noted in an advisory. "ADMIN or SYS_ADMIN authenticated users still have the ability to exploit the vulnerability when public signup is disabled."
The second vulnerability, CVE-2022-43782, concerns a misconfiguration in Crowd Server and Data Center that could permit an attacker to invoke privileged API endpoints, but only in scenarios where the bad actor is connecting from an IP address added to the Remote Address configuration.
Introduced in Crowd 3.0.0 and identified during an internal security review, the shortcoming impacts all new installations, meaning users who upgraded from a version prior to Crowd 3.0.0 are not vulnerable.
It's not uncommon for flaws in Atlassian and Bitbucket to be subjected to active exploitation in the wild, making it imperative that users move quickly to apply the patches.
Last month, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that a command injection flaw in Bitbucket Server and Data Center (CVE-2022-36804, CVSS score: 9.9) was being weaponized in attacks since late September 2022.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/11/atlassian-releases-patches-for-critical.html