← Back

CVE-2022-43781

nvd nist
Published: Nov 17, 2022Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the Bitbucket Server and Data Center instance has enabled “Allow public signup”.

Affected (8)

Products: Atlassian: Bitbucket
1 product
Bitbucket
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Atlassian
From 7.0.0 to 7.6.19
From 7.18.0 to 7.21.6
From 7.22.0 to 8.0.5
From 7.7.0 to 7.17.12
From 8.1.0 to 8.1.5
From 8.2.0 to 8.2.4
From 8.3.0 to 8.3.3
From 8.4.0 to 8.4.2

References (4)

Source: security@atlassian.com
MitigationRelease NotesVendor Advisory
Source: security@atlassian.com
Issue TrackingPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationRelease NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchVendor Advisory

Timeline

No history available yet.