CVE-2022-36804

HIGH KEV NUCLEI LAB

Atlassian Bitbucket Server/Data Center <7.6.17/<7.17.10/<7.21.4/<8....

Title source: llm

Description

Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21.4, from version 8.0.0 before version 8.0.3, from version 8.1.0 before version 8.1.3, and from version 8.2.0 before version 8.2.2, and from version 8.3.0 before 8.3.1 allows remote attackers with read permissions to a public or private Bitbucket repository to execute arbitrary code by sending a malicious HTTP request. This vulnerability was reported via our Bug Bounty Program by TheGrandPew.

Exploits (20)

exploitdb WORKING POC
by khal4n1 · textwebappspython
https://www.exploit-db.com/exploits/51040
nomisec WORKING POC 35 stars
by notdls · remote
https://github.com/notdls/CVE-2022-36804
nomisec WORKING POC 18 stars
by notxesh · remote
https://github.com/notxesh/CVE-2022-36804-PoC
nomisec WORKING POC 16 stars
by benjaminhays · remote-auth
https://github.com/benjaminhays/CVE-2022-36804-PoC-Exploit
nomisec WORKING POC 12 stars
by SystemVll · remote
https://github.com/SystemVll/CVE-2022-36804
nomisec WORKING POC 8 stars
by walnutsecurity · remote
https://github.com/walnutsecurity/cve-2022-36804
nomisec WORKING POC 7 stars
by kljunowsky · remote
https://github.com/kljunowsky/CVE-2022-36804-POC
nomisec WORKING POC 7 stars
by ColdFusionX · remote
https://github.com/ColdFusionX/CVE-2022-36804
nomisec WORKING POC 7 stars
by tahtaciburak · infoleak
https://github.com/tahtaciburak/cve-2022-36804
nomisec WORKING POC 3 stars
by khal4n1 · remote
https://github.com/khal4n1/CVE-2022-36804
nomisec SUSPICIOUS 3 stars
by Vulnmachines · remote
https://github.com/Vulnmachines/bitbucket-cve-2022-36804
nomisec WORKING POC 3 stars
by Chocapikk · remote-auth
https://github.com/Chocapikk/CVE-2022-36804-ReverseShell
nomisec STUB
by JohanGabrielson · poc
https://github.com/JohanGabrielson/bitbucket-test
nomisec WORKING POC
by DanielHallbro · remote
https://github.com/DanielHallbro/CVE-2022-36804-Bitbucket-RCE-Analysis
nomisec WORKING POC
by asepsaepdin · remote-auth
https://github.com/asepsaepdin/CVE-2022-36804
nomisec WORKING POC
by imbas007 · remote
https://github.com/imbas007/Atlassian-Bitbucket-CVE-2022-36804
nomisec SUSPICIOUS
by devengpk · poc
https://github.com/devengpk/CVE-2022-36804
nomisec WORKING POC
by 0xEleven · poc
https://github.com/0xEleven/CVE-2022-36804-ReverseShell
nomisec SUSPICIOUS
by JRandomSage · poc
https://github.com/JRandomSage/CVE-2022-36804-MASS-RCE
metasploit WORKING POC EXCELLENT
by TheGrandPew, Ron Bowes, Jang, Shelby Pace · rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/bitbucket_git_cmd_injection.rb

Nuclei Templates (1)

Atlassian Bitbucket - Remote Command Injection
HIGHby DhiyaneshDk,tess,sullo
Shodan: http.component:"BitBucket"

Scores

CVSS v3 8.8
EPSS 0.9440
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Lab Environment

COMMUNITY
Community Lab
docker pull kalilinux/kali-rolling
docker pull atlassian/bitbucket-server:7.17.1
docker pull atlassian/bitbucket:7.6.17
+16 more repos

Details

CISA KEV 2022-09-30
VulnCheck KEV 2022-09-30
InTheWild.io 2022-09-30
ENISA EUVD EUVD-2022-39504
CWE
CWE-78 CWE-88
Status published
Products (2)
atlassian/bitbucket 8.3.0
atlassian/bitbucket 7.0.0 - 7.6.17
Published Aug 25, 2022
KEV Added Sep 30, 2022
Tracked Since Feb 18, 2026