SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6, 7.18.0 and later prior to 7.18.4, 7.19.0 and later prior to 7.19.4, and 7.20.0 allow a remote, unauthenticated attacker to execute arbitrary code via Java deserialization.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 06:53
Type | Values Removed | Values Added |
---|---|---|
References | () https://confluence.atlassian.com/security/multiple-products-security-advisory-hazelcast-vulnerable-to-remote-code-execution-cve-2016-10750-1116292387.html - Patch, Vendor Advisory | |
References | () https://jira.atlassian.com/browse/BSERV-13173 - Vendor Advisory |
Information
Published : 2022-04-20 19:15
Updated : 2024-11-21 06:53
NVD link : CVE-2022-26133
Mitre link : CVE-2022-26133
CVE.ORG link : CVE-2022-26133
JSON object : View
Products Affected
atlassian
- bitbucket_data_center
CWE
CWE-502
Deserialization of Untrusted Data