CVE-2022-43781
65Vexday Risk Score
Corrija em breve. Ela tem exploit funcional público.
ssvc Attendcvss 9.8epss 98%
da publicação à arma0 dias
Publicada no NVD17 de nov.
metasploit16 de nov.
probabilidade de exploração
98%top 1% das CVEs
exploração observada
nãonenhuma fonte reporta
There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the Bitbucket Server and Data Center instance has enabled “Allow public signup”.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H