Remote Command Execution Vulnerability in Bitbucket Server and Data Center from Atlassian
CVE-2019-15000
9.8CRITICAL
Key Information:
- Vendor
- Atlassian
- Vendor
- CVE Published:
- 19 September 2019
Summary
A vulnerability in Atlassian's Bitbucket Server and Data Center allows remote attackers with repository access, potentially anonymously, to exploit public project settings. This exploitation enables unauthorized reading of arbitrary files and executing commands by injecting additional arguments into git commands, posing significant security risks to the system.
Affected Version(s)
Bitbucket Data Center < 5.16.10
Bitbucket Data Center 6.0.0
Bitbucket Data Center < 6.0.10
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved