OS Command Injection in Bitbucket Data Center and Bitbucket Server - CVE-2022-36804
Published: August 29, 2022 / Updated: February 25, 2025
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation within multiple API endpoints. A remote attacker with access to a public repository or read permissions to a private Bitbucket repository can send a specially crafted HTTP request and execute arbitrary OS commands on the server.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Bitbucket Server
How to mitigate CVE-2022-36804
Bitbucket Server - addressed in versions 7.6.17, 7.17.10, 7.21.4, 8.0.3, 8.1.3, 8.2.2, 8.3.1
Links to Public Exploits and PoC-codes
- Exploit #11173 - CVE-2022-36804-PoC-Exploit (Somewhat Reliable PoC Exploit for CVE-2022-36804 (BitBucket Critical Command Injection)) (February 25, 2025)
- Exploit #10664 - Bitbucket v7.0.0 - RCE (October 25, 2024)
- Exploit #9616 - CVE-2022-36804-ReverseShell (PoC exploit for CVE-2022-36804 (BitBucket Critical Command Injection)) (March 22, 2024)
- Exploit #8771 - cve-2022-36804 (A critical command injection vulnerability was found in multiple API endpoints of the Atlassian Bit bucket Server and Data center. This vulnerability affects all versions of Bitbucket Server and Data Center released before versions <7.6.17 (January 25, 2023)
- Exploit #8684 - CVE-2022-36804 () (December 20, 2022)
- Exploit #8541 - CVE-2022-36804 (You can find a python script to exploit the vulnerability on Bitbucket related CVE-2022-36804.) (October 26, 2022)
- Exploit #8443 - CVE-2022-36804 () (October 6, 2022)
- Exploit #8441 - CVE-2022-36804 (Atlassian Bitbucket Server and Data Center - Command Injection Vulnerability (CVE-2022-36804)) (October 4, 2022)
- Exploit #8423 - CVE-2022-36804-ReverseShell () (October 2, 2022)
- Exploit #8406 - CVE-2022-36804 (A loader for bitbucket 2022 rce (cve-2022-36804)) (September 26, 2022)
- Exploit #8397 - cve-2022-36804 (A simple PoC for Atlassian Bitbucket RCE [CVE-2022-36804]) (September 25, 2022)
- Exploit #8386 - Bitbucket Git Command Injection (September 21, 2022)
- Exploit #8382 - CVE-2022-36804-PoC-Exploit (Somewhat Reliable PoC Exploit for CVE-2022-36804 (BitBucket Critical Command Injection)) (September 20, 2022)
- Exploit #8381 - bitbucket-cve-2022-36804 (CVE-2022-36804 Atlassian Bitbucket Command Injection Vulnerability) (September 20, 2022)
- Exploit #8380 - CVE-2022-36804 (A real exploit for BitBucket RCE CVE-2022-36804) (September 19, 2022)
- Exploit #8377 - CVE-2022-36804-PoC (Multithreaded exploit script for CVE-2022-36804 affecting BitBucket versions <8.3.1) (September 19, 2022)