{"cvss":0.0,"datePublished":"2022-09-30","dateUpdated":"2022-09-30","description":"Multiple API endpoints of Atlassian Bitbucket Server and Data Center contain a command injection vulnerability where an attacker with access to a public Bitbucket repository, or with read permissions to a private one, can execute code by sending a malicious HTTP request.","dueDate":"2022-10-21","id":"CVE-2022-36804","kev_catalogs":["cisa"],"knownRansomwareCampaignUse":"Unknown","notes":"https://jira.atlassian.com/browse/BSERV-13438;  https://nvd.nist.gov/vuln/detail/CVE-2022-36804","product":"Bitbucket Server and Data Center","requiredAction":"Apply updates per vendor instructions.","severity":"HIGH","source":"cisa_known_exploited","title":"Atlassian Bitbucket Server and Data Center Command Injection Vulnerability","vendor":"Atlassian"}