CVE Database
/

CVE-2022-36804

Back to search

CVE-2022-36804

Published: Aug 25, 2022

Modified: Oct 21, 2025

PUBLISHED

Description

Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21.4, from version 8.0.0 before version 8.0.3, from version 8.1.0 before version 8.1.3, and from version 8.2.0 before version 8.2.2, and from version 8.3.0 before 8.3.1 allows remote attackers with read permissions to a public or private Bitbucket repository to execute arbitrary code by sending a malicious HTTP request. This vulnerability was reported via our Bug Bounty Program by TheGrandPew.

VendorProductVersions

Atlassian

Bitbucket Server

affected
7.0.0 - < unspecified
affected
unspecified - < 7.6.17
affected
7.7.0 - < unspecified
affected
unspecified - < 7.17.10
affected
7.18.0 - < unspecified

+9 more versions

Atlassian

Bitbucket Data Center

affected
7.0.0 - < unspecified
affected
unspecified - < 7.6.17
affected
7.7.0 - < unspecified
affected
unspecified - < 7.17.10
affected
7.18.0 - < unspecified

+9 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now