CVE-2022-26133
SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6, 7.18.0 and later prior to 7.18.4, 7.19.0 and later prior to 7.19.4, and 7.20.0 allow a remote, unauthenticated attacker to execute arbitrary code via Java deserialization.
- Affected products
- Bitbucket
- Atlassian Bitbucket Data Center
- < 7.6.14, 7.17.6, 7.18.4, 7.19.4, 7.20.0
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 70.4% (99th percentile)
- Weakness
- CWE-502
- NVD status
- Modified
- Published
- 2022-04-20
CVE-2022-26133 at NVD
4 known exploits for CVE-2022-26133
Proof-of-concept code and exploit modules indexed by Sploitus
Exploit for Deserialization of Untrusted Data in Atlassian Bitbucket_Data_Center
Exploit for Deserialization of Untrusted Data in Atlassian Bitbucket_Data_Center
Exploit for Deserialization of Untrusted Data in Atlassian Bitbucket_Data_Center
Exploit for Deserialization of Untrusted Data in Hazelcast