CVE Database
/

CVE-2019-15010

Back to search

CVE-2019-15010

Published: Jan 15, 2020

Modified: Sep 16, 2024

PUBLISHED

Description

Bitbucket Server and Bitbucket Data Center versions starting from version 3.0.0 before version 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.1.9, from version 6.2.0 before 6.2.7, from version 6.3.0 before 6.3.6, from version 6.4.0 before 6.4.4, from version 6.5.0 before 6.5.3, from version 6.6.0 before 6.6.3, from version 6.7.0 before 6.7.3, from version 6.8.0 before 6.8.2, and from version 6.9.0 before 6.9.1 had a Remote Code Execution vulnerability via certain user input fields. A remote attacker with user level permissions can exploit this vulnerability to run arbitrary commands on the victim's systems. Using a specially crafted payload as user input, the attacker can execute arbitrary commands on the victim's Bitbucket Server or Bitbucket Data Center instance.

VendorProductVersions

Atlassian

Bitbucket Server

affected
3.0 - < unspecified
affected
unspecified - < 5.16.11
affected
6.0 - < unspecified
affected
unspecified - < 6.0.11
affected
6.1.0 - < unspecified

+17 more versions

Atlassian

Bitbucket Data Center

affected
3.0 - < unspecified
affected
unspecified - < 5.16.11
affected
6.0 - < unspecified
affected
unspecified - < 6.0.11
affected
6.1.0 - < unspecified

+17 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now