Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3883-h64p-r3xm

Опубликовано: 06 июл. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the Bitbucket Server and Data Center instance has enabled “Allow public signup”.

There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the Bitbucket Server and Data Center instance has enabled “Allow public signup”.

EPSS

Процентиль: 100%
0.98076
Критический

9.8 Critical

CVSS3

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 9.8
nvd
почти 4 года назад

There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the Bitbucket Server and Data Center instance has enabled “Allow public signup”.

CVSS3: 9.8
fstec
почти 4 года назад

Уязвимость программного средства обработки данных Atlassian Bitbucket Data Center и Bitbucket Server, связанная с непринятием мер по чистке данных на управляющем уровне, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 100%
0.98076
Критический

9.8 Critical

CVSS3

Дефекты

CWE-77