Critical Vulnerability Discovered in Atlassian Bitbucket Server and Data Center
Aug 26, 2022
 Atlassian has rolled out fixes for a  critical security flaw  in Bitbucket Server and Data Center that could lead to the execution of malicious code on vulnerable installations.  Tracked as  CVE-2022-36804  (CVSS score: 9.9), the issue has been characterized as a command injection vulnerability in multiple endpoints that could be exploited via specially crafted HTTP requests.   "An attacker with access to a public Bitbucket repository or with read permissions to a private one can execute arbitrary code by sending a malicious HTTP request," Atlassian  said  in an advisory.  The shortcoming, discovered and reported by security researcher  @TheGrandPew  impacts all versions of Bitbucket Server and Datacenter released after 6.10.17, inclusive of 7.0.0 and newer -   Bitbucket Server and Datacenter 7.6  Bitbucket Server and Datacenter 7.17  Bitbucket Server and Datacenter 7.21  Bitbucket Server and Datacenter 8.0  Bitbucket Server and Datacenter 8.1  B...