Privilege Escalation in Atlassian Bitbucket Server and Data Center by Microsoft
CVE-2020-36233
7.8HIGH
Key Information:
- Vendor
Atlassian
- Vendor
- CVE Published:
- 18 February 2021
What is CVE-2020-36233?
The Atlassian Bitbucket Server and Data Center, specifically versions prior to 6.10.9 and 7.x before 7.6.4, are vulnerable to privilege escalation due to insufficient permission controls within the installation directory. Local attackers may exploit these weak permissions to gain elevated access, potentially compromising the system.
Affected Version(s)
Bitbucket Data Center < 6.10.9
Bitbucket Data Center 7.0.0
Bitbucket Data Center < 7.6.4