CVE-2022-26133

Severity
9.8CRITICAL
EPSS
81.4%
top 0.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 20
Latest updateApr 21

Description

SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6, 7.18.0 and later prior to 7.18.4, 7.19.0 and later prior to 7.19.4, and 7.20.0 allow a remote, unauthenticated attacker to execute arbitrary code via Java deserialization.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

CVEListV5atlassian/bitbucket_data_center5.14.0unspecified+8
NVDatlassian/bitbucket_data_center5.14.07.6.14+4

Patches

🔴Vulnerability Details

2
GHSA
GHSA-2p9p-h8q6-52g9: SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 52022-04-21
CVEList
CVE-2022-26133: SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 52022-04-20