CVE-2022-43781
65Vexday Risk Score
Corrige pronto. Ella tiene exploit funcional público.
ssvc Attendcvss 9.8epss 98%
de la publicación al arma0 días
Publicada en NVD17 nov
metasploit16 nov
probabilidad de explotación
98%top 1% de las CVE
explotación observada
noninguna fuente lo reporta
There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the Bitbucket Server and Data Center instance has enabled “Allow public signup”.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H