Known vulnerabilities in Bitbucket Server - page 4
Vendor:
Atlassian
Software:
Bitbucket Server
Software CPE:
cpe:2.3:a:atlassian:bitbucket_server:*:*:*:*:*:*:*:*
Website:
https://www.atlassian.com
Total vulnerabilities:
82
Public exploits:
13
Known exploited (KEV):
3
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
9.4.23
9.4.22
9.4.21
9.4.20
9.4.19
10.1.5
10.2.0
8.19.29
9.4.18
8.19.28
9.4.17
8.14.0-eap01
2.12.7
10.1.1
3.5.0
3.3.1
8.19.27
9.4.16
9.4.15
8.19.26
9.4.14
10.0.2
10.0.1
10.0.0
9.4.13
8.19.25
8.19.24
9.4.12
8.19.23
8.19.22
9.4.11
9.4.10
8.19.21
9.6.5
9.4.9
9.4.8
9.6.4
8.19.20
9.6.3
9.6.2
9.6.1
9.4.7
8.19.19
9.4.6
8.19.18
8.9.27
9.4.5
8.19.17
9.6.0
8.19.16
9.5.2
8.9.26
9.4.4
9.4.3
8.19.15
9.5.1
8.9.25
9.5.0
9.4.2
9.4.1
9.4.0
9.3.2
9.3.1
9.3.0
8.19.14
8.9.24
8.9.23
8.19.13
8.19.12
8.9.22
8.19.11
8.9.21
9.2.1
9.2.0
9.1.1
9.1.0
9.0.1
9.0.0
8.9.20
8.19.10
8.19.9
8.9.19
8.19.8
8.19.7
8.9.18
8.9.17
8.19.6
8.9.16
8.19.5
8.9.15
8.19.4
8.15.5
8.19.3
8.19.2
8.19.1
8.9.14
8.9.13
8.9.12
8.17.2
8.18.1
8.19.0
8.18.0
8.17.1
8.17.0
8.13.6
8.13.5
8.15.4
8.15.3
8.16.2
8.16.3
8.9.11
7.21.23
8.14.6
8.14.5
7.21.22
8.9.10
8.14.4
8.12.6
8.9.9
7.21.21
7.21.20
8.16.1
8.16.0
8.15.2
8.15.1
8.15.0
8.14.3
8.14.2
8.14.1
8.13.4
8.13.3
8.13.2
8.12.5
8.12.4
8.12.3
8.11.6
8.11.5
8.10.6
8.9.8
8.9.7
8.9.6
7.21.19
7.21.18
7.21.17
7.17.21
8.14.0
8.13.1
8.13.0
8.12.2
8.12.1
8.12.0
8.11.4
8.11.3
8.11.2
8.11.1
8.11.0
8.10.5
8.10.4
8.10.3
8.10.2
8.10.1
8.10.0
8.9.5
8.9.4
8.9.3
8.9.2
8.9.1
8.9.0
8.8.7
8.8.6
8.8.5
8.8.4
8.8.3
8.8.2
8.8.1
8.8.0
8.7.5
8.7.4
8.7.3
8.7.2
8.7.1
8.7.0
7.17.20
7.21.16
7.17.19
7.21.15
7.21.14
7.17.18
7.21.13
7.21.12
7.17.17
8.6.4
8.5.4
7.21.11
7.17.16
7.6.23
7.6.22
7.21.10
7.17.15
8.4.4
8.5.3
8.6.3
7.21.9
8.6.2
8.5.2
8.4.3
8.3.4
7.6.21
7.21.8
7.17.14
8.4.2
8.4.1
8.4.0
8.5.1
8.5.0
8.6.1
8.6.0
7.21.7
7.17.13
7.6.20
8.3.3
8.2.4
8.1.5
8.0.5
7.21.6
7.17.12
7.6.19
8.3.2
8.2.3
8.1.4
8.0.4
7.21.5
7.17.11
8.3.1
8.3.0
8.2.2
8.2.1
8.2.0
8.1.3
8.1.2
8.1.1
8.1.0
8.0.3
8.0.2
8.0.1
8.0.0
7.21.4
7.21.3
7.21.2
7.21.1
7.21.0
7.20.3
7.20.2
7.20.1
7.20.0
7.19.5
7.19.4
7.19.3
7.19.2
7.19.1
7.19.0
7.18.4
7.18.3
7.18.2
7.18.1
7.18.0
7.17.10
7.17.9
7.17.8
7.17.7
7.17.6
7.17.5
7.17.4
7.17.3
7.17.2
7.17.1
7.17.0
7.16.3
7.16.2
7.16.1
7.16.0
7.15.3
7.15.2
7.15.1
7.15.0
7.14.2
7.14.1
7.14.0
7.13.1
7.13.0
7.12.0
7.12.1
7.11.2
7.11.1
7.10.1
7.10.0
7.9.1
7.9.0
7.8.1
7.8.0
7.7.1
7.7.0
7.6.17
7.6.16
7.6.15
7.6.14
7.6.13
7.6.12
7.6.11
7.6.10
7.6.9
7.6.8
7.6.7
7.6.6
7.6.5
7.6.4
7.6.3
7.6.2
7.6.1
7.6.0
7.5.2
7.5.1
7.5.0
7.4.2
7.4.1
7.4.0
7.3.2
7.3.1
7.3.0
7.2.6
7.2.5
7.2.4
7.2.3
7.2.2
7.2.1
7.2.0
7.1.4
7.1.3
7.1.2
7.1.1
7.1.0
7.0.5
7.0.4
7.0.3
7.0.2
7.0.1
6.10.17
6.10.16
6.10.15
6.10.14
6.10.13
6.10.12
6.10.11
6.10.10
6.10.9
6.10.8
6.10.7
6.10.6
6.10.5
6.10.4
6.10.3
6.10.2
6.10.1
6.10.0
6.9.3
6.9.2
6.9.1
6.9.0
6.8.4
6.8.3
6.8.2
6.8.1
6.8.0
6.7.5
6.7.4
6.7.3
6.7.2
6.7.1
6.7.0
6.6.4
6.6.3
6.6.2
6.6.1
6.6.0
6.5.3
6.5.2
6.5.1
6.5.0
6.4.4
6.4.3
6.4.2
6.4.1
6.4.0
6.3.6
6.3.5
6.3.4
6.3.3
6.3.2
6.3.1
6.2.7
6.2.6
6.2.5
6.2.4
6.2.3
6.2.2
6.1.9
6.1.8
6.1.7
6.1.6
6.1.5
6.0.11
6.0.10
6.0.9
6.0.8
6.0.7
6.0.6
5.16.11
5.16.10
5.16.9
5.16.8
5.16.7
5.16.6
5.11.0
5.4.9
5.4.8
5.4.7
5.4.6
5.4.5
5.4.4
5.4.3
5.4.2
5.4.1
5.4.0
5.3.7
5.3.6
5.3.5
5.3.4
5.3.3
5.3.2
5.3.1
5.3.0
5.2.8
5.2.7
5.2.6
5.2.5
5.2.4
5.2.3
5.2.2
5.2.1
5.2.0
5.1.9
5.1.8
5.1.7
5.1.6
5.1.5
5.1.4
5.1.3
5.1.2
5.1.1
5.1.0
5.0.10
5.0.9
5.0.8
5.0.7
5.0.6
5.0.5
5.0.4
5.0.3
5.0.2
5.0.1
5.0.0
4.14.12
4.14.11
4.14.10
4.14.9
4.14.8
4.14.7
4.14.6
4.14.5
4.14.4
4.14.3
4.14.2
4.14.1
4.14.0
4.13.1
4.13.0
4.12.1
4.12.0
4.11.2
4.11.1
4.11.0
4.10.2
4.10.1
4.10.0
4.9.1
4.9.0
4.8.6
4.8.5
4.8.4
4.8.3
4.8.2
4.8.1
4.8.0
4.7.2
4.7.1
4.7.0
4.6.3
4.6.2
4.6.1
4.6.0
4.5.2
4.5.1
4.5.0
4.4.2
4.4.1
4.4.0
4.3.3
4.3.2
4.3.1
4.3.0
4.2.3
4.2.2
4.2.1
4.1.6
4.1.5
4.1.4
4.1.3
4.1.2
4.1.1
4.1.0
4.0.8
4.0.7
4.0.6
4.0.5
4.0.4
4.0.3
4.0.2
4.0.1
4.0.0
5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.5.6
5.5.7
5.5.8
5.5.9
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.7.0
5.7.1
5.7.2
5.7.3
5.7.4
5.8.0
5.8.1
5.8.2
5.8.3
5.8.4
5.9.0
5.9.1
5.9.2
5.10.0
5.10.1
5.10.2
5.10.3
5.10.4
5.11.1
5.11.2
5.11.3
5.11.4
5.12.0
5.12.1
5.12.2
5.12.3
5.12.4
5.13.0
5.13.1
5.13.3
5.13.4
5.13.5
5.13.6
5.14.0
5.14.1
5.14.2
5.14.3
5.14.4
5.15.0
5.15.1
5.15.2
5.15.3
5.16.0
5.16.1
5.16.2
5.16.3
5.16.4
5.16.5
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.1.0
6.1.1
6.1.2
6.1.3
6.1.4
4.2.0
6.2.0
6.2.1
6.3.0
Vulnerabilities (82)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU87607 - Improper Access Control CVE-2024-22257 |
CWE-284 | Medium | 8.9.12, 8.19.1 | 19.03.2024 |
SB2024031915 SB2024041659 SB2024041660 and 26 more |
||
| #VU86992 - Allocation of Resources Without Limits or Throttling CVE-2024-21634 |
CWE-770 | Medium | 7.21.22, 8.9.10, 8.13.6, 8.14.5, 8.15.4, 8.16.3, 8.17.2, 8.18.1 | 04.03.2024 |
SB2024030419 SB2024031125 SB2024032143 and 18 more |
||
| #VU85848 - Resource exhaustion CVE-2023-6481 |
CWE-400 | Medium | 7.21.19, 8.9.9, 8.13.5, 8.14.4, 8.15.3, 8.16.2, 8.17.0 | 29.01.2024 |
SB2024012902 SB2024020727 SB2024020840 and 23 more |
||
| #VU85618 - Deserialization of Untrusted Data CVE-2023-6378 |
CWE-502 | Medium | 7.21.19, 8.9.9, 8.13.5, 8.14.4, 8.15.3, 8.16.2, 8.17.0 | 19.01.2024 |
SB2024011926 SB2024011927 SB2024012316 and 39 more |
||
| #VU83533 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2023-46589 |
CWE-444 | Medium | 7.21.21, 8.9.9, 8.13.5, 8.14.4, 8.15.3, 8.16.2, 8.17.0 | 28.11.2023 |
SB2023112846 SB2023121851 SB2023122831 and 78 more |
||
| #VU82454 - Allocation of Resources Without Limits or Throttling CVE-2023-43642 |
CWE-770 | Medium | 7.21.21, 8.9.9, 8.13.5, 8.14.4, 8.15.3, 8.16.2, 8.17.0 | 26.10.2023 |
SB2023102621 SB2023102628 SB2023103020 and 63 more |
||
| #VU82276 - Allocation of Resources Without Limits or Throttling CVE-2023-5072 |
CWE-770 | Medium | 7.21.18, 8.9.7, 8.11.6, 8.12.4, 8.13.3, 8.14.2 | 20.10.2023 |
SB2023102017 SB2023102018 SB2023113056 and 97 more |
||
| #VU81728 - Resource exhaustion CVE-2023-44487 |
CWE-400 | High | 7.21.18, 8.9.7, 8.11.6, 8.12.4, 8.13.3, 8.14.2 | 10.10.2023 |
SB2023101023 SB2023101024 SB2023101037 and 650 more |
||
| #VU81726 - Integer overflow CVE-2023-36478 |
CWE-190 | Medium | 8.9.8, 8.13.4, 8.14.3, 8.15.2, 8.16.1 | 10.10.2023 |
SB2023101018 SB2023102640 SB2023103106 and 53 more |
||
| #VU81100 - Improper input validation CVE-2023-22513 |
CWE-20 | Medium | 8.9.5, 8.10.5, 8.11.4, 8.12.2, 8.13.1 | 25.09.2023 |
SB2023092532 |
||
| #VU80783 - Incorrect Conversion between Numeric Types CVE-2023-3635 |
CWE-681 | Medium | 7.21.18, 8.9.7, 8.11.6, 8.12.4, 8.13.3, 8.14.2 | 14.09.2023 |
SB2023091430 SB2023091528 SB2023100937 and 47 more |
||
| #VU77778 - Improper input validation CVE-2022-29546 |
CWE-20 | Low | 7.21.18, 8.9.7, 8.11.6, 8.12.4, 8.13.3, 8.14.2 | 28.06.2023 |
SB2022050443 SB20230719104 SB20231018117 and 10 more |
||
| #VU77777 - Improper input validation CVE-2022-28366 |
CWE-20 | Low | 7.21.18, 8.9.7, 8.11.6, 8.12.4, 8.13.3, 8.14.2 | 28.06.2023 |
SB2022042155 SB2023112475 SB2023121271 and 7 more |
||
| #VU70385 - Deserialization of Untrusted Data CVE-2022-1471 |
CWE-502 | High | 7.21.16, 8.8.7, 8.9.4, 8.10.4, 8.11.3, 8.12.1, 8.13.0, 8.14.0 | 15.12.2022 |
SB2022121539 SB2022121540 SB2022121928 and 124 more |
||
| #VU69408 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2022-43781 |
CWE-78 | High | 7.6.19, 7.17.12, 7.21.6, 8.0.5, 8.1.5, 8.2.4, 8.3.3, 8.4.2 | 18.11.2022 |
SB2022111807 |
||
| #VU66798 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2022-36804 |
CWE-78 | High | 7.6.17, 7.17.10, 7.21.4, 8.0.3, 8.1.3, 8.2.2, 8.3.1 | 29.08.2022 |
SB2022082908 |
||
| #VU65499 - Improper input validation CVE-2021-31684 |
CWE-20 | Medium | 7.21.18, 8.9.7, 8.11.6, 8.12.4, 8.13.3, 8.14.2 | 20.07.2022 |
SB2022072048 SB2022072056 SB2022112850 and 20 more |
||
| #VU65486 - Improper input validation CVE-2022-24839 |
CWE-20 | Medium | 7.21.18, 8.9.7, 8.11.6, 8.12.4, 8.13.3, 8.14.2 | 20.07.2022 |
SB2022072038 SB2022102803 SB2022102807 and 31 more |
||
| #VU58198 - Exposure of sensitive information to an unauthorized actor CVE-2021-40690 |
CWE-200 | Medium | 7.21.18 | 16.11.2021 |
SB2021111622 SB2021111712 SB2022012032 and 37 more |
||
| #VU48979 - Improper Restriction of XML External Entity Reference ('XXE') CVE-2020-25649 |
CWE-611 | Medium | 7.21.18, 8.9.7, 8.11.6, 8.12.4, 8.13.3, 8.14.2 | 03.12.2020 |
SB2020121510 SB2021020321 SB2021042112 and 68 more |
Showing elements 61 - 80 out of 82