CVE-2022-36804

HIGH(8.8)KEVLikely Exploited

Atlassian Bitbucket Server and Data Center Command Injection Vulnerability

Description

CVE-2022-36804 is a critical command injection vulnerability in Atlassian Bitbucket Server and Data Center that allows an attacker with access to a public repository or read permissions to a private one to execute arbitrary code by sending a malicious HTTP request to multiple API endpoints. The vulnerability enables remote code execution on the server hosting Bitbucket. With an EPSS score of 94.43% (99.98th percentile), this Bitbucket vulnerability is among the most actively exploited. CISA added CVE-2022-36804 to the KEV catalog on September 30, 2022.

KEV Information

Vendor
Atlassian
Product
Bitbucket Server and Data Center
Date Added
September 30, 2022
Due Date
October 21, 2022
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9

CWEs

Affected Products

VendorProductVersion
atlassianbitbucket>= 7.0.0, < 7.6.17; >= 7.7.0, < 7.17.10; >= 7.18.0, < 7.21.4; >= 8.0.0, < 8.0.3; >= 8.1.0, < 8.1.3; >= 8.2.0, < 8.2.2; 8.3.0

Multiple CVSS Assessments

Source: [email protected](Primary)
8.8
HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
8.8
HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References

Weakness Type

CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')

CVE-2022-36804 exploits a command injection weakness in Atlassian Bitbucket Server's API endpoints. User-supplied input in HTTP request parameters is incorporated into system commands without proper neutralization, allowing attackers to inject additional commands that execute on the underlying operating system.

Learn more: CWE-77 — Improper Neutralization of Special Elements used in a Command ('Command Injection')

Impact Analysis

CVE-2022-36804 is a critical command injection vulnerability that is exploitable from the network with low complexity. An attacker only needs read access to a repository (which is automatically granted for public repositories) to exploit the vulnerability — no administrative privileges or user interaction required. Confidentiality, integrity, and availability are all critically impacted: successful exploitation grants arbitrary command execution on the Bitbucket server, potentially exposing all source code repositories, credentials stored in the system, and enabling lateral movement across the development infrastructure. The EPSS score of 94.43% confirms widespread exploitation activity, and the targeting of source code repositories makes this vulnerability particularly valuable to threat actors.

Exploit Maturity

CISA confirmed active exploitation of CVE-2022-36804 and added it to the KEV catalog on September 30, 2022, with a remediation deadline of October 21, 2022. The EPSS score of 94.43% (99.98th percentile) indicates near-certain exploitation activity. Public proof-of-concept exploits are widely available, and the vulnerability is actively exploited by threat actors targeting software development infrastructure. The ransomware association is classified as unknown, but source code theft and supply chain compromise are significant risks.

Remediation

  1. Update Bitbucket Server/Data Center: Upgrade to Bitbucket Server 7.6.17, 7.17.10, 7.21.4, 8.0.3, 8.1.3, 8.2.2, 8.3.1, or later versions that address this command injection vulnerability.
  2. Restrict public repository access: As an interim measure, disable public repository access to limit exploitation to authenticated users only, reducing the attack surface.
  3. Apply network-level restrictions: Use a Web Application Firewall (WAF) or reverse proxy to filter malicious request patterns targeting the vulnerable API endpoints.
  4. Audit repository access logs: Review Bitbucket access logs for unusual API requests, particularly those containing command injection payloads in request parameters.
  5. Rotate credentials: After patching, rotate all credentials stored in Bitbucket repositories, CI/CD pipeline configurations, and any secrets that may have been exposed during the vulnerability window.

Technical Details

CVE-2022-36804 is a command injection vulnerability in multiple API endpoints of Atlassian Bitbucket Server and Data Center. The flaw exists in how the server processes user input in HTTP request parameters that are passed to system-level commands, specifically in git operations executed by the server. When processing certain API requests, user-supplied values are incorporated into command-line arguments without adequate sanitization, allowing an attacker to inject shell metacharacters that break out of the intended command context and execute arbitrary operating system commands. The vulnerability requires only repository read access, which is granted by default for public repositories, making it exploitable by any user with network access to a Bitbucket instance hosting public repositories.

Frequently Asked Questions

Is CVE-2022-36804 being actively exploited?

Yes, CVE-2022-36804 is actively exploited. CISA added it to the KEV catalog on September 30, 2022, and the EPSS score of 94.43% confirms near-certain exploitation activity. Public exploits are widely available.

What products are affected by CVE-2022-36804?

CVE-2022-36804 affects Atlassian Bitbucket Server and Data Center versions from 7.0.0 up to but not including the patched versions (7.6.17, 7.17.10, 7.21.4, 8.0.3, 8.1.3, 8.2.2, 8.3.1). Bitbucket Cloud is not affected.

How do I fix CVE-2022-36804?

Update Bitbucket Server or Data Center to the latest patched version. As an interim measure, disable public repository access to reduce the attack surface.

How severe is CVE-2022-36804?

CVE-2022-36804 is a critical command injection vulnerability with an EPSS score of 94.43% (99.98th percentile). It allows attackers with minimal access to execute arbitrary code on the Bitbucket server.

CVSS Score

8.8
HIGH(8.8)

EPSS Score

EPSS Score99.08%
EPSS Percentile99.9%

Dates

PublishedAugust 25, 2022
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.