CRITICAL

CVE-2022-43781

CVSS v3

9.8

CRITICAL

EPSS Score

92.1%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the Bitbucket Server and Data Center instance has enabled “Allow public signup”.

Technical details

Published
11/17/2022

Frequently asked questions

What is CVE-2022-43781?

There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the Bitbucket Server and Data Center instance has enabled “Allow public signup”.

Is CVE-2022-43781 actively exploited?

Active exploitation of CVE-2022-43781 has not been confirmed. The EPSS score is 92.1%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2022-43781?

CVE-2022-43781 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2022-43781 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.