A critical vulnerability (CVE-2022-43781) has been identified in Bitbucket Server, a package for deploying a web interface for working with git repositories, allowing a remote attacker to achieve code execution on the server. This vulnerability can be exploited by an unauthenticated user if self-registration is enabled on the server (the 'Allow public signup' setting is turned on). It can also be exploited by an authenticated user with permissions to change their username (i.e., those with ADMIN or SYS_ADMIN privileges). Details are not yet provided; it is only known that the issue is caused by the ability to inject commands via environment variables.
The issue manifests in versions 7.x and 8.x and has been resolved in Bitbucket Server and Bitbucket Data Center releases 8.5.0, 8.4.2, 7.17.12, 7.21.6, 8.0.5, 8.1.5, 8.3.3, 8.2.4, and 7.6.19. The vulnerability does not appear in the cloud service bitbucket.org and affects only on-premises products. The issue also does not occur on servers Bitbucket Server and Data Center where PostgreSQL is used as the database management system.
Source: opennet.ru
