Unrated severityNVD Advisory· Published Nov 17, 2022· Updated Oct 2, 2024
CVE-2022-43781
CVE-2022-43781
Description
There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the Bitbucket Server and Data Center instance has enabled “Allow public signup”.
Affected products
2- Atlassian/Bitbucket Data Centerv5Range: before 7.17.12
- Range: before 7.17.12
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.