HIGH CISA KEV

CVE-2022-36804

CVSS v3

8.8

HIGH

EPSS Score

94.4%

exploit probability

CISA KEV

Yes

known exploited

Exploitation

SSVC status

Description

Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21.4, from version 8.0.0 before version 8.0.3, from version 8.1.0 before version 8.1.3, and from version 8.2.0 before version 8.2.2, and from version 8.3.0 before 8.3.1 allows remote attackers with read permissions to a public or private Bitbucket repository to execute arbitrary code by sending a malicious HTTP request. This vulnerability was reported via our Bug Bounty Program by TheGrandPew.

CISA Known Exploited Vulnerability

Date Added
9/30/2022
Patch Due Date
10/21/2022
Ransomware Use
Unknown

Technical details

Published
8/25/2022
Exploit-DB
EDB-51040

Frequently asked questions

What is CVE-2022-36804?

Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21.4, from version 8.0.0 before version 8.0.3, from version 8.1.0 before version 8.1.3, and from version 8.2.0 before version 8.2.2, and from version 8.3.0 before 8.3.1 allows remote attackers with read permissions to a public or private Bitbucket repository to execute arbitrary code by sending a malicious HTTP request. This vulnerability was reported via our Bug Bounty Program by TheGrandPew.

Is CVE-2022-36804 actively exploited?

Yes. CVE-2022-36804 is on the CISA Known Exploited Vulnerabilities (KEV) catalog, meaning it has been confirmed as actively exploited in the wild. CISA requires federal agencies to patch by 10/21/2022.

What is the CVSS score for CVE-2022-36804?

CVE-2022-36804 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2022-36804 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.