CVE Database
/

CVE-2019-15000

Back to search

CVE-2019-15000

Published: Sep 19, 2019

Modified: Sep 17, 2024

PUBLISHED

Description

The commit diff rest endpoint in Bitbucket Server and Data Center before 5.16.10 (the fixed version for 5.16.x ), from 6.0.0 before 6.0.10 (the fixed version for 6.0.x), from 6.1.0 before 6.1.8 (the fixed version for 6.1.x), from 6.2.0 before 6.2.6 (the fixed version for 6.2.x), from 6.3.0 before 6.3.5 (the fixed version for 6.3.x), from 6.4.0 before 6.4.3 (the fixed version for 6.4.x), and from 6.5.0 before 6.5.2 (the fixed version for 6.5.x) allows remote attackers who have permission to access a repository, if public access is enabled for a project or repository then attackers are able to exploit this issue anonymously, to read the contents of arbitrary files on the system and execute commands via injecting additional arguments into git commands.

VendorProductVersions

Atlassian

Bitbucket Server

affected
unspecified - < 5.16.10
affected
6.0.0 - < unspecified
affected
unspecified - < 6.0.10
affected
6.1.0 - < unspecified
affected
unspecified - < 6.1.8

+8 more versions

Atlassian

Bitbucket Data Center

affected
unspecified - < 5.16.10
affected
6.0.0 - < unspecified
affected
unspecified - < 6.0.10
affected
6.1.0 - < unspecified
affected
unspecified - < 6.1.8

+8 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now