Is Atlassian Bitbucket Server or Data Center patched against CVE-2022-36804?

/static/assets/linux-logo.svg
In Atlassian Bitbucket Server and Data Center there is a command injection vulnerability in multiple API endpoints. This TTP sends a curl request that will attempt to execute a command `cat /etc/passwd` on the remote host. An attacker with read permissions on a public or private Bitbucket repository can execute arbitrary code by sending a malicious HTTP request.
locked
View Command

To view this TTPs command, you must be logged in with a professional or enterprise license.

Login

Test this TTP

Download Operator (1.7.1)
Test this TTP using one of our Operator chains
Is Atlassian Bitbucket Server or Data Center patched against CVE-2022-36804?

2022-10-10

/static/assets/linux-logo.svg
Atlassian Bitbucker Server and Data Center code injection vulnerability