CVE Database
/

CVE-2019-20097

Back to search

CVE-2019-20097

Published: Jan 15, 2020

Modified: Sep 16, 2024

PUBLISHED

Description

Bitbucket Server and Bitbucket Data Center versions starting from 1.0.0 before 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.1.9, from version 6.2.0 before 6.2.7, from version 6.3.0 before 6.3.6, from version 6.4.0 before 6.4.4, from version 6.5.0 before 6.5.3, from version 6.6.0 before 6.6.3, from version 6.7.0 before 6.7.3, from version 6.8.0 before 6.8.2, from version 6.9.0 before 6.9.1 had a Remote Code Execution vulnerability via the post-receive hook. A remote attacker with permission to clone and push files to a repository on the victim's Bitbucket Server or Bitbucket Data Center instance, can exploit this vulnerability to execute arbitrary commands on the Bitbucket Server or Bitbucket Data Center systems, using a file with specially crafted content.

VendorProductVersions

Atlassian

Bitbucket Server

affected
1.0 - < unspecified
affected
unspecified - < 5.16.11
affected
6.0 - < unspecified
affected
unspecified - < 6.0.11
affected
6.1.0 - < unspecified

+17 more versions

Atlassian

Bitbucket Data Center

affected
1.0 - < unspecified
affected
unspecified - < 5.16.11
affected
6.0 - < unspecified
affected
unspecified - < 6.0.11
affected
6.1.0 - < unspecified

+17 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now