Bitbucket
Atlassian · 20 CVEs
There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker…
Nov 17, 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 be…
Aug 25, 2022
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Fi…
Jul 20, 2022
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used…
Jul 20, 2022
The Microsoft Windows Installer for Atlassian Bitbucket Server and Data Center before version 6.10.9, 7.x before 7.6.4,…
Feb 18, 2021
Webhooks in Atlassian Bitbucket Server from version 5.4.0 before version 7.3.1 allow remote attackers to access the con…
Jul 9, 2020
Atlassian Bitbucket Server from version 4.9.0 before version 7.2.4 allows remote attackers to intercept unencrypted rep…
Jul 9, 2020
Bitbucket Server and Bitbucket Data Center versions starting from 1.0.0 before 5.16.11, from version 6.0.0 before 6.0.1…
Jan 15, 2020
Bitbucket Server and Bitbucket Data Center from version 4.13. before 5.16.11, from version 6.0.0 before 6.0.11, from ve…
Jan 15, 2020
Bitbucket Server and Bitbucket Data Center versions starting from version 3.0.0 before version 5.16.11, from version 6.…
Jan 15, 2020
The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate…
Nov 8, 2019
The commit diff rest endpoint in Bitbucket Server and Data Center before 5.16.10 (the fixed version for 5.16.x ), from…
Sep 19, 2019
Atlassian Bitbucket Data Center licensed instances starting with version 5.13.0 before 5.13.6 (the fixed version for 5.…
Jun 3, 2019
In browser editing in Atlassian Bitbucket Server from version 4.13.0 before 5.4.8 (the fixed version for 4.13.0 through…
Mar 22, 2018
Various plugin servlet resources in Atlassian Bitbucket Server before version 5.3.7 (the fixed version for 5.3.x), from…
Feb 15, 2018
The download commit resource in Atlassian Bitbucket Server from version 5.1.0 before version 5.1.7, from version 5.2.0…
Feb 15, 2018
The repository settings resource in Atlassian Bitbucket Server before version 5.6.0 allows remote attackers to read the…
Feb 2, 2018
The git repository tag rest resource in Atlassian Bitbucket Server from version 3.7.0 before 4.14.11 (the fixed version…
Feb 2, 2018
The Github repository importer in Atlassian Bitbucket Server before version 5.3.0 allows remote attackers to determine…
Feb 2, 2018
Atlassian Bitbucket Server before 4.7.1 allows remote attackers to read the first line of an arbitrary file via a direc…
Apr 10, 2017
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2022-43781 | There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their userna… | CRITICAL | 98.08% | Nov 17, 2022 |
| CVE-2022-36804 KEV | Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.… | HIGH | 99.17% | Aug 25, 2022 |
| CVE-2022-26137 | A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application… | HIGH | 2.34% | Jul 20, 2022 |
| CVE-2022-26136 | A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impa… | CRITICAL | 5.35% | Jul 20, 2022 |
| CVE-2020-36233 | The Microsoft Windows Installer for Atlassian Bitbucket Server and Data Center before version 6.10.9, 7.x before 7.6.4, and from version 7.7.0 before 7.10.1 al… | HIGH | 0.27% | Feb 18, 2021 |
| CVE-2020-14170 | Webhooks in Atlassian Bitbucket Server from version 5.4.0 before version 7.3.1 allow remote attackers to access the content of internal network resources via a… | MEDIUM | 0.83% | Jul 9, 2020 |
| CVE-2020-14171 | Atlassian Bitbucket Server from version 4.9.0 before version 7.2.4 allows remote attackers to intercept unencrypted repository import requests via a Man-in-the… | MEDIUM | 0.56% | Jul 9, 2020 |
| CVE-2019-20097 | Bitbucket Server and Bitbucket Data Center versions starting from 1.0.0 before 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.1.9, from… | HIGH | 2.48% | Jan 15, 2020 |
| CVE-2019-15012 | Bitbucket Server and Bitbucket Data Center from version 4.13. before 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.1.9, from version 6… | HIGH | 1.60% | Jan 15, 2020 |
| CVE-2019-15010 | Bitbucket Server and Bitbucket Data Center versions starting from version 3.0.0 before version 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 be… | HIGH | 2.57% | Jan 15, 2020 |
| CVE-2019-15005 | The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results… | MEDIUM | 1.33% | Nov 8, 2019 |
| CVE-2019-15000 | The commit diff rest endpoint in Bitbucket Server and Data Center before 5.16.10 (the fixed version for 5.16.x ), from 6.0.0 before 6.0.10 (the fixed version f… | CRITICAL | 7.79% | Sep 19, 2019 |
| CVE-2019-3397 | Atlassian Bitbucket Data Center licensed instances starting with version 5.13.0 before 5.13.6 (the fixed version for 5.13.x), from 5.14.0 before 5.14.4 (fixed… | CRITICAL | 4.40% | Jun 3, 2019 |
| CVE-2018-5225 | In browser editing in Atlassian Bitbucket Server from version 4.13.0 before 5.4.8 (the fixed version for 4.13.0 through 5.4.7), 5.5.0 before 5.5.8 (the fixed v… | CRITICAL | 3.43% | Mar 22, 2018 |
| CVE-2017-18088 | Various plugin servlet resources in Atlassian Bitbucket Server before version 5.3.7 (the fixed version for 5.3.x), from version 5.4.0 before 5.4.6 (the fixed v… | MEDIUM | 0.99% | Feb 15, 2018 |
| CVE-2017-18087 | The download commit resource in Atlassian Bitbucket Server from version 5.1.0 before version 5.1.7, from version 5.2.0 before version 5.2.5, from version 5.3.0… | HIGH | 1.76% | Feb 15, 2018 |
| CVE-2017-18038 | The repository settings resource in Atlassian Bitbucket Server before version 5.6.0 allows remote attackers to read the first line of arbitrary files via a pat… | MEDIUM | 1.45% | Feb 2, 2018 |
| CVE-2017-18037 | The git repository tag rest resource in Atlassian Bitbucket Server from version 3.7.0 before 4.14.11 (the fixed version for 4.14.x), from version 5.0.0 before… | MEDIUM | 1.30% | Feb 2, 2018 |
| CVE-2017-18036 | The Github repository importer in Atlassian Bitbucket Server before version 5.3.0 allows remote attackers to determine if a service they could not otherwise re… | MEDIUM | 0.88% | Feb 2, 2018 |
| CVE-2016-4320 | Atlassian Bitbucket Server before 4.7.1 allows remote attackers to read the first line of an arbitrary file via a directory traversal attack on the pull reques… | MEDIUM | 1.75% | Apr 10, 2017 |
Showing 1 to 20 of 20 CVEs