Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21.4, from version 8.0.0 before version 8.0.3, from version 8.1.0 before version 8.1.3, and from version 8.2.0 before version 8.2.2, and from version 8.3.0 before 8.3.1 allows remote attackers with read permissions to a public or private Bitbucket repository to execute arbitrary code by sending a malicious HTTP request. This vulnerability was reported via our Bug Bounty Program by TheGrandPew.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: atlassian
Published: 2022-08-25T05:40:08.899310Z
Updated: 2024-09-16T18:14:18.941Z
Reserved: 2022-07-26T00:00:00
Link: CVE-2022-36804
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-08-25T06:15:09.077
Modified: 2024-11-21T07:13:48.687
Link: CVE-2022-36804
Redhat
No data.