A critical vulnerability (CVE-2022-36804) has been identified in Bitbucket Server, a package for deploying a web interface for working with git repositories, allowing a remote attacker with read access to private or public repositories to execute arbitrary code on the server by sending a specially crafted HTTP request. The issue manifests starting from version 6.10.17 and has been patched in Bitbucket Server and Bitbucket Data Center releases 7.6.17, 7.17.10, 7.21.4, 8.0.3, 8.2.2, and 8.3.1. The vulnerability does not affect the cloud service bitbucket.org and only impacts self-hosted products.
The vulnerability was discovered by a security researcher as part of the Bugcrowd Bug Bounty initiative, which offers rewards for the discovery of previously unknown vulnerabilities. The reward amounted to $6,000. Details about the attack method and a prototype exploit are promised to be disclosed 30 days after the patch release. As a precaution to mitigate the risk of attack on their systems before applying the fix, it is advised to restrict public access to repositories using the setting 'feature.public.access=false'.
Source: opennet.ru
