Bitbucket Server and Bitbucket Data Center versions starting from 1.0.0 before 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.1.9, from version 6.2.0 before 6.2.7, from version 6.3.0 before 6.3.6, from version 6.4.0 before 6.4.4, from version 6.5.0 before 6.5.3, from version 6.6.0 before 6.6.3, from version 6.7.0 before 6.7.3, from version 6.8.0 before 6.8.2, from version 6.9.0 before 6.9.1 had a Remote Code Execution vulnerability via the post-receive hook. A remote attacker with permission to clone and push files to a repository on the victim's Bitbucket Server or Bitbucket Data Center instance, can exploit this vulnerability to execute arbitrary commands on the Bitbucket Server or Bitbucket Data Center systems, using a file with specially crafted content.
References
Link Resource
https://jira.atlassian.com/browse/BSERV-12099 Issue Tracking Patch Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: atlassian

Published: 2020-01-15T00:00:00

Updated: 2020-01-15T20:46:56

Reserved: 2019-12-30T00:00:00


Link: CVE-2019-20097

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-01-15T21:15:12.483

Modified: 2020-08-24T17:37:01.140


Link: CVE-2019-20097

JSON object: View

cve-icon Redhat Information

No data.