CVE-2022-36804
⚠ KEVEPSS 94.4%Atlassian Bitbucket Server and Data Center Command Injection Vulnerability
Added to CISA KEV: 9/30/2022
Description
Multiple API endpoints of Atlassian Bitbucket Server and Data Center contain a command injection vulnerability where an attacker with access to a public Bitbucket repository, or with read permissions to a private one, can execute code by sending a malicious HTTP request.
Affected packages (0)
No package mapping in OSV.