CVE-2022-36804

HIGH KEV NUCLEI

Atlassian Bitbucket Server/Data Center <7.6.17/<7.17.10/<7.21.4/<8....

Title source: llm

Description

Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21.4, from version 8.0.0 before version 8.0.3, from version 8.1.0 before version 8.1.3, and from version 8.2.0 before version 8.2.2, and from version 8.3.0 before 8.3.1 allows remote attackers with read permissions to a public or private Bitbucket repository to execute arbitrary code by sending a malicious HTTP request. This vulnerability was reported via our Bug Bounty Program by TheGrandPew.

Exploits (19)

nomisec WORKING POC 35 stars
by notdls · remote
https://github.com/notdls/CVE-2022-36804
nomisec WORKING POC 18 stars
by notxesh · remote
https://github.com/notxesh/CVE-2022-36804-PoC
nomisec WORKING POC 16 stars
by benjaminhays · remote-auth
https://github.com/benjaminhays/CVE-2022-36804-PoC-Exploit
nomisec WORKING POC 12 stars
by SystemVll · remote
https://github.com/SystemVll/CVE-2022-36804
nomisec WORKING POC 8 stars
by walnutsecurity · remote
https://github.com/walnutsecurity/cve-2022-36804
nomisec WORKING POC 7 stars
by ColdFusionX · remote
https://github.com/ColdFusionX/CVE-2022-36804
nomisec WORKING POC 7 stars
by tahtaciburak · infoleak
https://github.com/tahtaciburak/cve-2022-36804
nomisec WORKING POC 7 stars
by kljunowsky · remote
https://github.com/kljunowsky/CVE-2022-36804-POC
nomisec WORKING POC 3 stars
by khal4n1 · remote
https://github.com/khal4n1/CVE-2022-36804
nomisec SUSPICIOUS 3 stars
by Vulnmachines · remote
https://github.com/Vulnmachines/bitbucket-cve-2022-36804
nomisec WORKING POC 3 stars
by Chocapikk · remote-auth
https://github.com/Chocapikk/CVE-2022-36804-ReverseShell
nomisec WORKING POC
by asepsaepdin · remote-auth
https://github.com/asepsaepdin/CVE-2022-36804
nomisec WORKING POC
by imbas007 · remote
https://github.com/imbas007/Atlassian-Bitbucket-CVE-2022-36804
nomisec WORKING POC
by DanielHallbro · remote
https://github.com/DanielHallbro/CVE-2022-36804-Bitbucket-RCE-Analysis
nomisec SUSPICIOUS
by devengpk · poc
https://github.com/devengpk/CVE-2022-36804
nomisec SUSPICIOUS
by JRandomSage · poc
https://github.com/JRandomSage/CVE-2022-36804-MASS-RCE
nomisec WORKING POC
by 0xEleven · poc
https://github.com/0xEleven/CVE-2022-36804-ReverseShell
metasploit WORKING POC EXCELLENT
by TheGrandPew, Ron Bowes, Jang, Shelby Pace · rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/bitbucket_git_cmd_injection.rb
exploitdb WORKING POC
by khal4n1 · textwebappspython
https://www.exploit-db.com/exploits/51040

Nuclei Templates (1)

Atlassian Bitbucket - Remote Command Injection
HIGHby DhiyaneshDk,tess,sullo
Shodan: http.component:"BitBucket"

Scores

CVSS v3 8.8
EPSS 0.9443
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Exploitation Intel

CISA KEV 2022-09-30
VulnCheck KEV 2022-09-30
InTheWild.io 2022-09-30
ENISA EUVD EUVD-2022-39504

Classification

CWE
CWE-78 CWE-88
Status published

Affected Products (2)

atlassian/bitbucket < 7.6.17
atlassian/bitbucket

Timeline

Published Aug 25, 2022
KEV Added Sep 30, 2022
Tracked Since Feb 18, 2026