Known vulnerabilities in Bitbucket Server - page 4

Vendor: Atlassian
Software CPE: cpe:2.3:a:atlassian:bitbucket_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 82
Public exploits: 13
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Bitbucket Server Bitbucket Server is affected by 82 known vulnerabilities: 1 critical, 11 high, 64 medium, 6 low Critical High Medium Low

Vulnerabilities (82)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU87607 - Improper Access Control
CVE-2024-22257
CWE-284 Medium
No
No
8.9.12, 8.19.1 19.03.2024 SB2024031915
SB2024041659
SB2024041660
and 26 more
#VU86992 - Allocation of Resources Without Limits or Throttling
CVE-2024-21634
CWE-770 Medium
No
No
7.21.22, 8.9.10, 8.13.6, 8.14.5, 8.15.4, 8.16.3, 8.17.2, 8.18.1 04.03.2024 SB2024030419
SB2024031125
SB2024032143
and 18 more
#VU85848 - Resource exhaustion
CVE-2023-6481
CWE-400 Medium
No
No
7.21.19, 8.9.9, 8.13.5, 8.14.4, 8.15.3, 8.16.2, 8.17.0 29.01.2024 SB2024012902
SB2024020727
SB2024020840
and 23 more
#VU85618 - Deserialization of Untrusted Data
CVE-2023-6378
CWE-502 Medium
No
No
7.21.19, 8.9.9, 8.13.5, 8.14.4, 8.15.3, 8.16.2, 8.17.0 19.01.2024 SB2024011926
SB2024011927
SB2024012316
and 39 more
#VU83533 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2023-46589
CWE-444 Medium
No
No
7.21.21, 8.9.9, 8.13.5, 8.14.4, 8.15.3, 8.16.2, 8.17.0 28.11.2023 SB2023112846
SB2023121851
SB2023122831
and 78 more
#VU82454 - Allocation of Resources Without Limits or Throttling
CVE-2023-43642
CWE-770 Medium
No
No
7.21.21, 8.9.9, 8.13.5, 8.14.4, 8.15.3, 8.16.2, 8.17.0 26.10.2023 SB2023102621
SB2023102628
SB2023103020
and 63 more
#VU82276 - Allocation of Resources Without Limits or Throttling
CVE-2023-5072
CWE-770 Medium
No
No
7.21.18, 8.9.7, 8.11.6, 8.12.4, 8.13.3, 8.14.2 20.10.2023 SB2023102017
SB2023102018
SB2023113056
and 97 more
#VU81728 - Resource exhaustion
CVE-2023-44487
CWE-400 High
Available
Exploited
7.21.18, 8.9.7, 8.11.6, 8.12.4, 8.13.3, 8.14.2 10.10.2023 SB2023101023
SB2023101024
SB2023101037
and 650 more
#VU81726 - Integer overflow
CVE-2023-36478
CWE-190 Medium
No
No
8.9.8, 8.13.4, 8.14.3, 8.15.2, 8.16.1 10.10.2023 SB2023101018
SB2023102640
SB2023103106
and 53 more
#VU81100 - Improper input validation
CVE-2023-22513
CWE-20 Medium
No
No
8.9.5, 8.10.5, 8.11.4, 8.12.2, 8.13.1 25.09.2023 SB2023092532
#VU80783 - Incorrect Conversion between Numeric Types
CVE-2023-3635
CWE-681 Medium
No
No
7.21.18, 8.9.7, 8.11.6, 8.12.4, 8.13.3, 8.14.2 14.09.2023 SB2023091430
SB2023091528
SB2023100937
and 47 more
#VU77778 - Improper input validation
CVE-2022-29546
CWE-20 Low
No
No
7.21.18, 8.9.7, 8.11.6, 8.12.4, 8.13.3, 8.14.2 28.06.2023 SB2022050443
SB20230719104
SB20231018117
and 10 more
#VU77777 - Improper input validation
CVE-2022-28366
CWE-20 Low
No
No
7.21.18, 8.9.7, 8.11.6, 8.12.4, 8.13.3, 8.14.2 28.06.2023 SB2022042155
SB2023112475
SB2023121271
and 7 more
#VU70385 - Deserialization of Untrusted Data
CVE-2022-1471
CWE-502 High
Available
No
7.21.16, 8.8.7, 8.9.4, 8.10.4, 8.11.3, 8.12.1, 8.13.0, 8.14.0 15.12.2022 SB2022121539
SB2022121540
SB2022121928
and 124 more
#VU69408 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-43781
CWE-78 High
Available
No
7.6.19, 7.17.12, 7.21.6, 8.0.5, 8.1.5, 8.2.4, 8.3.3, 8.4.2 18.11.2022 SB2022111807
#VU66798 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-36804
CWE-78 High
Available
Exploited
7.6.17, 7.17.10, 7.21.4, 8.0.3, 8.1.3, 8.2.2, 8.3.1 29.08.2022 SB2022082908
#VU65499 - Improper input validation
CVE-2021-31684
CWE-20 Medium
No
No
7.21.18, 8.9.7, 8.11.6, 8.12.4, 8.13.3, 8.14.2 20.07.2022 SB2022072048
SB2022072056
SB2022112850
and 20 more
#VU65486 - Improper input validation
CVE-2022-24839
CWE-20 Medium
No
No
7.21.18, 8.9.7, 8.11.6, 8.12.4, 8.13.3, 8.14.2 20.07.2022 SB2022072038
SB2022102803
SB2022102807
and 31 more
#VU58198 - Exposure of sensitive information to an unauthorized actor
CVE-2021-40690
CWE-200 Medium
No
No
7.21.18 16.11.2021 SB2021111622
SB2021111712
SB2022012032
and 37 more
#VU48979 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2020-25649
CWE-611 Medium
No
No
7.21.18, 8.9.7, 8.11.6, 8.12.4, 8.13.3, 8.14.2 03.12.2020 SB2020121510
SB2021020321
SB2021042112
and 68 more


Showing elements 61 - 80 out of 82