SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6, 7.18.0 and later prior to 7.18.4, 7.19.0 and later prior to 7.19.4, and 7.20.0 allow a remote, unauthenticated attacker to execute arbitrary code via Java deserialization.
References
Link | Resource |
---|---|
https://jira.atlassian.com/browse/BSERV-13173 | Vendor Advisory |
https://confluence.atlassian.com/security/multiple-products-security-advisory-hazelcast-vulnerable-to-remote-code-execution-cve-2016-10750-1116292387.html | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-04-20 12:15
Updated : 2022-04-28 10:50
NVD link : CVE-2022-26133
Mitre link : CVE-2022-26133
JSON object : View
CWE
CWE-502
Deserialization of Untrusted Data
Products Affected
atlassian
- bitbucket_data_center