CVE-2022-26133: critical vulnerability in Atlassian Bitbucket Data Center
Published · Updated
75Vexday Risk Score
Keep watching. It has a public proof of concept.
ssvc Attendcvss 9.8epss 70%
from disclosure to weapon19 days
Published on NVDApr 20
1st PoC+19d
exploitation probability
70%top 1% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6, 7.18.0 and later prior to 7.18.4, 7.19.0 and later prior to 7.19.4, and 7.20.0 allow a remote, unauthenticated attacker to execute arbitrary code via Java deserialization.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Atlassian · Bitbucket Data Centerpublic PoCs found — 2
githubgithub.com/Pear1y/CVE-2022-26133★ 147githubgithub.com/abbarhissarh/CVE-2022-26133★ 3⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Related CVEs — Atlassian Bitbucket Data Center
In the same product, most dangerous first.