CVE-2022-26133

EUVD-2022-30700
SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6, 7.18.0 and later prior to 7.18.4, 7.19.0 and later prior to 7.19.4, and 7.20.0 allow a remote, unauthenticated attacker to execute arbitrary code via Java deserialization.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
Affected Products (NVD)
VendorProductVersion
atlassianbitbucket_data_center
5.14.0 ≤
𝑥
< 7.6.14
atlassianbitbucket_data_center
7.7.0 ≤
𝑥
< 7.17.6
atlassianbitbucket_data_center
7.18.0 ≤
𝑥
< 7.18.4
atlassianbitbucket_data_center
7.19.0 ≤
𝑥
< 7.19.4
atlassianbitbucket_data_center
7.20.0
𝑥
= Vulnerable software versions