CVE-2022-26133

SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6, 7.18.0 and later prior to 7.18.4, 7.19.0 and later prior to 7.19.4, and 7.20.0 allow a remote, unauthenticated attacker to execute arbitrary code via Java deserialization.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
atlassianbitbucket_data_center
5.14.0 ≤
𝑥
< 7.6.14
atlassianbitbucket_data_center
7.7.0 ≤
𝑥
< 7.17.6
atlassianbitbucket_data_center
7.18.0 ≤
𝑥
< 7.18.4
atlassianbitbucket_data_center
7.19.0 ≤
𝑥
< 7.19.4
atlassianbitbucket_data_center
7.20.0
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
atlassianbitbucket_data_center
5.14.0 ≤
𝑥
< 7.6.14
ADP
atlassianbitbucket_data_center
7.7.0 ≤
𝑥
< 7.17.6
ADP
atlassianbitbucket_data_center
7.18.0 ≤
𝑥
< 7.18.4
ADP
atlassianbitbucket_data_center
7.19.0 ≤
𝑥
< 7.19.4
ADP