
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2022-43781 is a critical command injection vulnerability affecting Bitbucket Server and Data Center, discovered and disclosed on November 16, 2022. The vulnerability was introduced in version 7.0.0 and affects all versions from 7.0 to 7.21, as well as versions 8.0 to 8.4 if mesh.enabled is set to false in bitbucket.properties. This security flaw allows attackers with permission to control their username to execute arbitrary code on the system (Atlassian Advisory, NVD).
The vulnerability exploits environment variables in Bitbucket Server and Data Center through command injection. The functionality involved in making user name changes uses the \u0000 character as a delimiter, allowing for injection of environment variables into the user name if input such as username\u0000ENV_VAR=VALUE is used. The vulnerability has received a CVSS v3.1 base score of 9.8 (Critical), with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating network accessibility, low attack complexity, and no required privileges or user interaction (AttackerKB).
The vulnerability enables attackers to execute arbitrary code on the affected system, potentially leading to complete system compromise. The impact is particularly severe when the 'Allow public signup' feature is enabled, as it allows unauthenticated exploitation. The vulnerability affects both Bitbucket Server and Data Center installations, though instances running PostgreSQL are not affected (Atlassian Advisory).
The vulnerability can be exploited by attackers who can control their username, which typically includes users in admin and sys-admin groups. If 'Allow public signup' is enabled, the vulnerability becomes exploitable without authentication. Exploit attempts can be detected through various indicators including length restrictions on usernames, logging of name change requests, and persistent GIT_EXTERNAL_DIFF environment variable settings (AttackerKB).
Atlassian recommends upgrading to fixed versions: 7.6.19 or newer, 7.17.12 or newer, 7.21.6 or newer, 8.0.5 or newer, 8.1.5 or newer, 8.2.4 or newer, 8.3.3 or newer, 8.4.2 or newer, or 8.5.0 or newer. As a temporary mitigation, organizations can disable the 'Public Signup' feature through Administration > Authentication settings, though this only reduces the attack vector from unauthenticated to authenticated access. Note that ADMIN or SYS_ADMIN users can still exploit the vulnerability even with public signup disabled (Atlassian Advisory).
The vulnerability was discovered and reported by security researcher @Ry0taK. Atlassian has rated the severity of this vulnerability as critical according to their severity levels scale (Atlassian Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."