Atlassian's Bitbucket buggy, needs patch

By

Remote code execution vulnerability disclosed.

The server and data centre versions of Atlassian’s Bitbucket software have a critical command injection vulnerability.

Atlassian's Bitbucket buggy, needs patch

Part of the company’s DevOps offering, Bitbucket is a Git-based code hosting service integrated with Jira.

There are free and commercial plans, and Bitbucket supports an unlimited number of private repositories. 

According to Atlassian, the bug was introduced in version 7.0.0 of Bitbucket, and “all versions released after 6.10.17” are affected, so “all instances that are running any versions between 7.0.0 and 8.3.0 inclusive are affected by this vulnerability.”

Designated CVE-2022-36804, the issue is in multiple API endpoints of Bitbucket Server and Data Center. 

“An attacker with access to a public repository or with read permissions to a private Bitbucket repository can execute arbitrary code by sending a malicious HTTP request”, the advisory explains.

Cloud sites hosted at bitbucket.org are not affected.

Twitter user @TheGrandPew, who discovered the bug and reported it through Atlassian’s bug bounty program, has promised proof-of-concept code in 30 days.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

CBA using facial recognition logins to verify disputed payments

CBA using facial recognition logins to verify disputed payments

Qantas obtains court order to prevent third-party access to stolen data

Qantas obtains court order to prevent third-party access to stolen data

Cloudflare makes changes to avoid repeat of 1.1.1.1 DNS outage

Cloudflare makes changes to avoid repeat of 1.1.1.1 DNS outage

Researchers demo AI-crippling GPUHammer attack

Researchers demo AI-crippling GPUHammer attack

Log In

  |  Forgot your password?