Bitbucket OAuth Credentials Exposure
Detects exposed auth.json files containing Bitbucket OAuth credentials
共找到 8 条公开漏洞记录
Detects exposed auth.json files containing Bitbucket OAuth credentials
There is a permission bypass vulnerability through %20, which allows arbitrary users to obtain sensitive data
Bitbucket Public Repository is exposed.
There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the Bitbucket Server and Data Center instance has enabled “Allow public signup”.
Atlassian Bitbucket Server and Data Center is susceptible to remote command injection. Multiple API endpoints can allow an attacker with read permissions to a public or private Bitbucket repository to execute arbitrary code by sending a malicious HTTP request, thus making it possible to obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials. Affected versions are 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21.4, from version 8.0.0 before version 8.0.3, from version 8.1.0 before version 8.1.3, and from version 8.2.0 before version 8.2.2, and from version 8.3.0 before 8.3.1.
Bitbucket Data Center 使用第三方软件 Hazelcast,该软件容易受到 Java 反序列化攻击 ( CVE-2022-26133 )。Hazelcast 提供了将 Bitbucket Data Center 作为集群运行所需的功能。未经身份验证的远程攻击者可以通过发送特制请求来利用此漏洞,从而执行任意代码。 影响版本: Bitbucket Server 及 Bitbucket Cloud 不受影响。 Bitbucket Data Center以下版本受到影响: ● 所有 5.x 版本 >= 5.14.x ● 所有 6.x 版本 ● 所有 7.x 版本 < 7.6.14 ● 所有版本 7.7.x 到 7.16.x ● 7.17.x < 7.17.6 ● 7.18.x < 7.18.4 ● 7.19.x < 7.19.4 ● 7.20.0 以下版本的 Bitbucket Data Center 修复了此漏洞: ● 7.6.14 ● 7.17.6 ● 7.18.4 ● 7.19.4 ● 7.20.1 ● 7.21.0