Skip to main content

Vendor/product archive

atlassian / bitbucket CVEs

Beta · best-effort

20 CVEs tagged to atlassian / bitbucket5 Critical, 7 High, 8 Medium, 0 Low, 0 Unrated.

CVE-2022-43781

Published Nov 17, 2022

There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2022-36804

Published Aug 25, 2022

Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.2…

CVSS 8.8 · High
evidence mentions
8
Buzz score
65.1
KEV listedPublic PoC observed
Vendor/product tagsBeta · best-effort

CVE-2022-26137

Published Jul 20, 2022

A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5

CVE-2022-26136

Published Jul 20, 2022

A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2020-36233

Published Feb 18, 2021

The Microsoft Windows Installer for Atlassian Bitbucket Server and Data Center before version 6.10.9, 7.x before 7.6.4, and from version 7.7.0 before 7.10.1 allows local attackers…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-14171

Published Jul 9, 2020

Atlassian Bitbucket Server from version 4.9.0 before version 7.2.4 allows remote attackers to intercept unencrypted repository import requests via a Man-in-the-Middle (MITM) attac…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-14170

Published Jul 9, 2020

Webhooks in Atlassian Bitbucket Server from version 5.4.0 before version 7.3.1 allow remote attackers to access the content of internal network resources via a Server-Side Request…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-20097

Published Jan 15, 2020

Bitbucket Server and Bitbucket Data Center versions starting from 1.0.0 before 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.1.9, from version 6.2.0 befor…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-15012

Published Jan 15, 2020

Bitbucket Server and Bitbucket Data Center from version 4.13. before 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.1.9, from version 6.2.0 before 6.2.7, f…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-15010

Published Jan 15, 2020

Bitbucket Server and Bitbucket Data Center versions starting from version 3.0.0 before version 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.1.9, from ver…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-15000

Published Sep 19, 2019

The commit diff rest endpoint in Bitbucket Server and Data Center before 5.16.10 (the fixed version for 5.16.x ), from 6.0.0 before 6.0.10 (the fixed version for 6.0.x), from 6.1.…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-3397

Published Jun 3, 2019

Atlassian Bitbucket Data Center licensed instances starting with version 5.13.0 before 5.13.6 (the fixed version for 5.13.x), from 5.14.0 before 5.14.4 (fixed version for 5.14.x),…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-5225

Published Mar 22, 2018

In browser editing in Atlassian Bitbucket Server from version 4.13.0 before 5.4.8 (the fixed version for 4.13.0 through 5.4.7), 5.5.0 before 5.5.8 (the fixed version for 5.5.x), 5…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-18088

Published Feb 15, 2018

Various plugin servlet resources in Atlassian Bitbucket Server before version 5.3.7 (the fixed version for 5.3.x), from version 5.4.0 before 5.4.6 (the fixed version for 5.4.x), f…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18087

Published Feb 15, 2018

The download commit resource in Atlassian Bitbucket Server from version 5.1.0 before version 5.1.7, from version 5.2.0 before version 5.2.5, from version 5.3.0 before version 5.3.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-18038

Published Feb 2, 2018

The repository settings resource in Atlassian Bitbucket Server before version 5.6.0 allows remote attackers to read the first line of arbitrary files via a path traversal vulnerab…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18037

Published Feb 2, 2018

The git repository tag rest resource in Atlassian Bitbucket Server from version 3.7.0 before 4.14.11 (the fixed version for 4.14.x), from version 5.0.0 before 5.0.9 (the fixed ver…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18036

Published Feb 2, 2018

The Github repository importer in Atlassian Bitbucket Server before version 5.3.0 allows remote attackers to determine if a service they could not otherwise reach has open ports v…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-4320

Published Apr 10, 2017

Atlassian Bitbucket Server before 4.7.1 allows remote attackers to read the first line of an arbitrary file via a directory traversal attack on the pull requests resource.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-20 of 20 CVEsPage 1 of 1