Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21.4, from version 8.0.0 before version 8.0.3, from version 8.1.0 before version 8.1.3, and from version 8.2.0 before version 8.2.2, and from version 8.3.0 before 8.3.1 allows remote attackers with read permissions to a public or private Bitbucket repository to execute arbitrary code by sending a malicious HTTP request. This vulnerability was reported via our Bug Bounty Program by TheGrandPew.
Metrics
Affected Vendors & Products
References
History
Tue, 21 Oct 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 21 Oct 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 21 Oct 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Sun, 09 Feb 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-Other |
Wed, 29 Jan 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-78 CWE-88 |
|
| Metrics |
kev
|
Status: PUBLISHED
Assigner: atlassian
Published: 2022-08-25T05:40:08.899Z
Updated: 2025-10-21T23:15:36.273Z
Reserved: 2022-07-26T00:00:00.000Z
Link: CVE-2022-36804
Updated: 2024-08-03T10:14:28.471Z
Status : Analyzed
Published: 2022-08-25T06:15:09.077
Modified: 2025-10-24T13:37:44.367
Link: CVE-2022-36804
No data.