Atlassian Releases Patches for Critical Flaws Affecting Crowd and Bitbucket Products

Share:

Australian software company Atlassian has rolled out security updates to address two critical flaws affecting Bitbucket Server, Data Center, and Crowd products.

The issues, tracked as CVE-2022-43781 and CVE-2022-43782, are both rated 9 out of 10 on the CVSS vulnerability scoring system.

CVE-2022-43781, which Atlassian said was introduced in version 7.0.0 of Bitbucket Server and Data Center, affects versions 7.0 to 7.21 and 8.0 to 8.4 (only if mesh.enabled is set to false in bitbucket.properties).

The weakness has been described as a case of command injection using environment variables in the software, which could allow an adversary with permission to control their username to gain code execution on the affected system.

As a temporary workaround, the company is recommending users turn off the “Public Signup” option (Administration > Authentication).

“Disabling public signup would change the attack vector from an unauthenticated attack to an authenticated one which would reduce the risk of exploitation,” it noted in an advisory. “ADMIN or SYS_ADMIN authenticated users still have the ability to exploit the vulnerability when public signup is disabled.”

The second vulnerability, CVE-2022-43782, concerns a misconfiguration in Crowd Server and Data Center that could permit an attacker to invoke privileged API endpoints, but only in scenarios where the bad actor is connecting from an IP address added to the Remote Address configuration.

Introduced in Crowd 3.0.0 and identified during an internal security review, the shortcoming impacts all new installations, meaning users who upgraded from a version prior to Crowd 3.0.0 are not vulnerable.

It’s not uncommon for flaws in Atlassian and Bitbucket to be subjected to active exploitation in the wild, making it imperative that users move quickly to apply the patches.

Last month, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that a command injection flaw in Bitbucket Server and Data Center (CVE-2022-36804, CVSS score: 9.9) was being weaponized in attacks since late September 2022.

https://thehackernews.com/2022/11/atlassian-releases-patches-for-critical.html

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
2:35 am, Jul 11, 2025
weather icon 19°C
L: 17° | H: 20°
broken clouds
Humidity: 78 %
Pressure: 1021 mb
Wind: 5 mph E
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 60%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:56 am
Sunset: 9:15 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
17° | 20°°C 0 mm 0% 8 mph 77 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
19° | 30°°C 0 mm 0% 10 mph 66 % 1019 mb 0 mm/h
Sun Jul 13 10:00 pm
weather icon
18° | 30°°C 0 mm 0% 7 mph 71 % 1015 mb 0 mm/h
Mon Jul 14 10:00 pm
weather icon
18° | 28°°C 1 mm 100% 15 mph 84 % 1016 mb 0 mm/h
Tue Jul 15 10:00 pm
weather icon
14° | 20°°C 1 mm 100% 14 mph 81 % 1017 mb 0 mm/h
Today 4:00 am
weather icon
17° | 19°°C 0 mm 0% 3 mph 77 % 1021 mb 0 mm/h
Today 7:00 am
weather icon
19° | 19°°C 0 mm 0% 2 mph 73 % 1021 mb 0 mm/h
Today 10:00 am
weather icon
24° | 27°°C 0 mm 0% 2 mph 56 % 1021 mb 0 mm/h
Today 1:00 pm
weather icon
30° | 30°°C 0 mm 0% 3 mph 32 % 1020 mb 0 mm/h
Today 4:00 pm
weather icon
32° | 32°°C 0 mm 0% 4 mph 26 % 1018 mb 0 mm/h
Today 7:00 pm
weather icon
30° | 30°°C 0 mm 0% 6 mph 29 % 1017 mb 0 mm/h
Today 10:00 pm
weather icon
23° | 23°°C 0 mm 0% 8 mph 49 % 1019 mb 0 mm/h
Tomorrow 1:00 am
weather icon
21° | 21°°C 0 mm 0% 5 mph 57 % 1019 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€99,029.99
4.28%
Ethereum(ETH)
€2,516.47
6.28%
Tether(USDT)
€0.85
-0.03%
XRP(XRP)
€2.17
5.32%
Solana(SOL)
€140.50
4.69%
USDC(USDC)
€0.85
-0.01%
Dogecoin(DOGE)
€0.165492
7.50%
Shiba Inu(SHIB)
€0.000011
7.73%
Pepe(PEPE)
€0.000010
12.59%
Peanut the Squirrel(PNUT)
€0.244588
21.42%
Scroll to Top