CVE-2022-43781
There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the Bitbucket Server and Data Center instance has enabled “Allow public signup”.
- Affected products
- Bitbucket, Bitbucket Server
- Atlassian Bitbucket
- < 7.6.19, 7.17.12, 7.21.6, 8.0.5, 8.1.5, 8.2.4, 8.3.3, 8.4.2
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 98.1% (100th percentile)
- Weakness
- CWE-77
- NVD status
- Modified
- Published
- 2022-11-17
CVE-2022-43781 at NVD
3 known exploits for CVE-2022-43781
Proof-of-concept code and exploit modules indexed by Sploitus