CVE-2022-26133

SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6, 7.18.0 and later prior to 7.18.4, 7.19.0 and later prior to 7.19.4, and 7.20.0 allow a remote, unauthenticated attacker to execute arbitrary code via Java deserialization.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
atlassianCNA
---
---
CVEADP
---
---
CISA-ADPADP
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
atlassianbitbucket_data_center
5.14.0 ≤
𝑥
< 7.6.14
atlassianbitbucket_data_center
7.7.0 ≤
𝑥
< 7.17.6
atlassianbitbucket_data_center
7.18.0 ≤
𝑥
< 7.18.4
atlassianbitbucket_data_center
7.19.0 ≤
𝑥
< 7.19.4
atlassianbitbucket_data_center
7.20.0
𝑥
= Vulnerable software versions