Cyber Security News

Critical Atlassian Bitbucket Server and Data Center Flaw Let Attackers Execute Malicious Code

Atlassian revealed a critical security flaw in Bitbucket Server and Data Center that allows attackers to execute malicious code on vulnerable instances. The critical flaw is tracked as (CVE-2022-36804), a command injection vulnerability found in multiple API endpoints of Bitbucket Server and Data Center.

Vulnerability Details

Bitbucket is a Git-based source code repository hosting service owned by Atlassian. Bitbucket offers both commercial plans and free accounts with an unlimited number of private repositories.

Bitbucket Server and Data Center – Command injection vulnerability received a CVSS severity score of 9.9. According to the scale published in Atlassian severity levels, the severity level of this vulnerability is ‘Critical’.

“An attacker with access to a public repository or with read permissions to a private Bitbucket repository can execute arbitrary code by sending a malicious HTTP request”, reads the Advisory published by Atlassian.

Affected and Fixed Versions

All versions released after 6.10.17 including 7.0.0 and newer are affected, this means that all instances that are running any versions between 7.0.0 and 8.3.0 inclusive are affected by this vulnerability.

Further, the company states that users who access Bitbucket via a bitbucket.org domain, it is hosted by Atlassian, and users are not affected by the vulnerability.

Fixed Versions

Update Now

Atlassian advises the users to upgrade the instance to one of the versions listed in the “Fixed Versions” table. Also, if you have configured Bitbucket Mesh nodes, these will need to be updated with the corresponding version of Mesh that includes the fix.

Those who are unsure whether your Bitbucket instance has Bitbucket Mesh configured, as a user with system administration privileges navigate to Administration > Bitbucket Mesh, this page will list Mesh nodes each of which will need to be upgraded.

If you’re unable to upgrade Bitbucket, the company recommends applying temporary partial mitigation by turning off public repositories using “feature.public.access=false”.

Download Free SWG – Secure Web Filtering – E-book

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

5 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

5 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

6 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

8 hours ago