Remote Command Execution Vulnerability in Bitbucket Server and Data Center from Atlassian
CVE-2019-15000

9.8CRITICAL

Key Information:

Vendor
Atlassian
Vendor
CVE Published:
19 September 2019

Summary

A vulnerability in Atlassian's Bitbucket Server and Data Center allows remote attackers with repository access, potentially anonymously, to exploit public project settings. This exploitation enables unauthorized reading of arbitrary files and executing commands by injecting additional arguments into git commands, posing significant security risks to the system.

Affected Version(s)

Bitbucket Data Center < 5.16.10

Bitbucket Data Center 6.0.0

Bitbucket Data Center < 6.0.10

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.