Auto-merge PR#7011

Auto-merge PR#7011
This commit is contained in:
CVE Team 2022-08-25 01:40:35 -04:00 committed by GitHub
commit f01250f4b3
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -1,18 +1,177 @@
{
"data_type": "CVE",
"data_format": "MITRE",
"data_version": "4.0",
"CVE_data_meta": {
"ASSIGNER": "security@atlassian.com",
"DATE_PUBLIC": "2022-08-24T00:00:00",
"ID": "CVE-2022-36804",
"ASSIGNER": "cve@mitre.org",
"STATE": "RESERVED"
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "Bitbucket Server",
"version": {
"version_data": [
{
"version_value": "7.0.0",
"version_affected": ">="
},
{
"version_value": "7.6.17",
"version_affected": "<"
},
{
"version_value": "7.7.0",
"version_affected": ">="
},
{
"version_value": "7.17.10",
"version_affected": "<"
},
{
"version_value": "7.18.0",
"version_affected": ">="
},
{
"version_value": "7.21.4",
"version_affected": "<"
},
{
"version_value": "8.0.0",
"version_affected": ">="
},
{
"version_value": "8.0.3",
"version_affected": "<"
},
{
"version_value": "8.1.0",
"version_affected": ">="
},
{
"version_value": "8.1.3",
"version_affected": "<"
},
{
"version_value": "8.2.0",
"version_affected": ">="
},
{
"version_value": "8.2.2",
"version_affected": "<"
},
{
"version_value": "8.3.0",
"version_affected": ">="
},
{
"version_value": "8.3.1",
"version_affected": "<"
}
]
}
},
{
"product_name": "Bitbucket Data Center",
"version": {
"version_data": [
{
"version_value": "7.0.0",
"version_affected": ">="
},
{
"version_value": "7.6.17",
"version_affected": "<"
},
{
"version_value": "7.7.0",
"version_affected": ">="
},
{
"version_value": "7.17.10",
"version_affected": "<"
},
{
"version_value": "7.18.0",
"version_affected": ">="
},
{
"version_value": "7.21.4",
"version_affected": "<"
},
{
"version_value": "8.0.0",
"version_affected": ">="
},
{
"version_value": "8.0.3",
"version_affected": "<"
},
{
"version_value": "8.1.0",
"version_affected": ">="
},
{
"version_value": "8.1.3",
"version_affected": "<"
},
{
"version_value": "8.2.0",
"version_affected": ">="
},
{
"version_value": "8.2.2",
"version_affected": "<"
},
{
"version_value": "8.3.0",
"version_affected": ">="
},
{
"version_value": "8.3.1",
"version_affected": "<"
}
]
}
}
]
},
"vendor_name": "Atlassian"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided."
"value": "Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21.4, from version 8.0.0 before version 8.0.3, from version 8.1.0 before version 8.1.3, and from version 8.2.0 before version 8.2.2, and from version 8.3.0 before 8.3.1 allows remote attackers with read permissions to a public or private Bitbucket repository to execute arbitrary code by sending a malicious HTTP request. This vulnerability was reported via our Bug Bounty Program by TheGrandPew."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Remote Code Execution"
}
]
}
]
},
"references": {
"reference_data": [
{
"url": "https://jira.atlassian.com/browse/BSERV-13438"
}
]
}
}
}