{"id":20258,"date":"2022-10-03T16:10:37","date_gmt":"2022-10-04T00:10:37","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2022\/10\/03\/news-13991\/"},"modified":"2022-10-03T16:10:37","modified_gmt":"2022-10-04T00:10:37","slug":"news-13991","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2022\/10\/03\/news-13991\/","title":{"rendered":"Actively exploited vulnerability in Bitbucket Server and Data Center"},"content":{"rendered":"<p>On September 29, 2022 the Cybersecurity &amp; Infrastructure Security Agency (CISA) added&nbsp;three vulnerabilities to the <a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" target=\"_blank\">catalog of known to be exploited vulnerabilities<\/a>. One of them is <a href=\"https:\/\/www.cisa.gov\/uscert\/ncas\/current-activity\/2022\/09\/23\/cisa-has-added-one-known-exploited-vulnerability-catalog\" target=\"_blank\">a vulnerability in Atlassian&rsquo;s Bitbucket Server and Data Center<\/a>. The other two are the <a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2022\/09\/two-new-exchange-zero-days-that-look-and-feel-like-proxyshell-part-2\">Exchange Server zero-day vulnerabilities<\/a> we wrote about last week.<\/p>\n<p>The Bitbucket vulnerability is no zero-day. Fixed versions were made available on August 24, 2022. The vulnerability allows an attacker who has read permissions to execute arbitrary code by sending a malicious HTTP request.<\/p>\n<h2>Mitigation<\/h2>\n<p>All versions of Bitbucket Server and Datacenter released after 6.10.17 including 7.0.0 and newer are affected. Atlassian recommends that you upgrade your instance to one of the versions listed below.<\/p>\n<table class=\"MsoNormalTable\" border=\"1\" cellpadding=\"0\" width=\"613\" style=\"width: 460pt; background: white; border: 1pt solid #dfe1e6; margin-left: auto; margin-right: auto;\">\n<tbody>\n<tr style=\"height: 30.0pt;\">\n<td style=\"border: solid #DFE1E6 1.0pt; background: #FAFBFC; padding: 0cm 7.5pt 0cm 7.5pt; height: 30.0pt;\">\n<p style=\"margin: 0cm 0cm 8pt; line-height: 107%; font-size: 11pt; font-family: Calibri, sans-serif;\"><b><span style=\"color: black;\">Supported Version<\/span><\/b><\/p>\n<\/td>\n<td style=\"border: solid #DFE1E6 1.0pt; background: #FAFBFC; padding: 0cm 7.5pt 0cm 7.5pt; height: 30.0pt;\">\n<p style=\"margin: 0cm 0cm 8pt; line-height: 107%; font-size: 11pt; font-family: Calibri, sans-serif;\"><b><span style=\"color: black;\">Bug Fix Release<\/span><\/b><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" style=\"border: solid #DFE1E6 1.0pt; padding: 7.5pt 7.5pt 7.5pt 7.5pt;\">\n<p style=\"margin: 0cm 0cm 8pt; line-height: 107%; font-size: 11pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\"><a href=\"https:\/\/confluence.atlassian.com\/bitbucketserver\/bitbucket-server-7-6-release-notes-1018780800.html\" style=\"color: #0563c1; text-decoration: underline;\">Bitbucket Server and Data Center 7.6<\/a><\/span><\/p>\n<\/td>\n<td valign=\"top\" style=\"border: solid #DFE1E6 1.0pt; padding: 7.5pt 7.5pt 7.5pt 7.5pt;\">\n<p style=\"margin: 0cm 0cm 8pt; line-height: 107%; font-size: 11pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\">7.6.17 (<a href=\"https:\/\/confluence.atlassian.com\/enterprise\/long-term-support-releases-948227420.html\" style=\"color: #0563c1; text-decoration: underline;\">LTS<\/a>) or newer<\/span><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" style=\"border: solid #DFE1E6 1.0pt; padding: 7.5pt 7.5pt 7.5pt 7.5pt;\">\n<p style=\"margin: 0cm 0cm 8pt; line-height: 107%; font-size: 11pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\"><a href=\"https:\/\/confluence.atlassian.com\/bitbucketserver\/bitbucket-data-center-and-server-7-17-release-notes-1086401305.html\" style=\"color: #0563c1; text-decoration: underline;\">Bitbucket Server and Data Center 7.17<\/a><\/span><\/p>\n<\/td>\n<td valign=\"top\" style=\"border: solid #DFE1E6 1.0pt; padding: 7.5pt 7.5pt 7.5pt 7.5pt;\">\n<p style=\"margin: 0cm 0cm 8pt; line-height: 107%; font-size: 11pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\">7.17.10 (<a href=\"https:\/\/confluence.atlassian.com\/enterprise\/long-term-support-releases-948227420.html\" style=\"color: #0563c1; text-decoration: underline;\">LTS<\/a>) or newer<\/span><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" style=\"border: solid #DFE1E6 1.0pt; padding: 7.5pt 7.5pt 7.5pt 7.5pt;\">\n<p style=\"margin: 0cm 0cm 8pt; line-height: 107%; font-size: 11pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\"><a href=\"https:\/\/confluence.atlassian.com\/bitbucketserver\/bitbucket-data-center-and-server-7-21-release-notes-1115129015.html\" style=\"color: #0563c1; text-decoration: underline;\">Bitbucket Server and Data Center 7.21<\/a><\/span><\/p>\n<\/td>\n<td valign=\"top\" style=\"border: solid #DFE1E6 1.0pt; padding: 7.5pt 7.5pt 7.5pt 7.5pt;\">\n<p style=\"margin: 0cm 0cm 8pt; line-height: 107%; font-size: 11pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\">7.21.4 (<a href=\"https:\/\/confluence.atlassian.com\/enterprise\/long-term-support-releases-948227420.html\" style=\"color: #0563c1; text-decoration: underline;\">LTS<\/a>) or newer<\/span><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" style=\"border: solid #DFE1E6 1.0pt; padding: 7.5pt 7.5pt 7.5pt 7.5pt;\">\n<p style=\"margin: 0cm 0cm 8pt; line-height: 107%; font-size: 11pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\"><a href=\"https:\/\/confluence.atlassian.com\/bitbucketserver\/bitbucket-data-center-and-server-8-0-release-notes-1115659343.html\" style=\"color: #0563c1; text-decoration: underline;\">Bitbucket Server and Data Center 8.0<\/a><\/span><\/p>\n<\/td>\n<td valign=\"top\" style=\"border: solid #DFE1E6 1.0pt; padding: 7.5pt 7.5pt 7.5pt 7.5pt;\">\n<p style=\"margin: 0cm 0cm 8pt; line-height: 107%; font-size: 11pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\">8.0.3 or newer<\/span><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" style=\"border: solid #DFE1E6 1.0pt; padding: 7.5pt 7.5pt 7.5pt 7.5pt;\">\n<p style=\"margin: 0cm 0cm 8pt; line-height: 107%; font-size: 11pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\"><a href=\"https:\/\/confluence.atlassian.com\/bitbucketserver\/bitbucket-data-center-and-server-8-1-release-notes-1130726463.html\" style=\"color: #0563c1; text-decoration: underline;\">Bitbucket Server and Data Center 8.1<\/a><\/span><\/p>\n<\/td>\n<td valign=\"top\" style=\"border: solid #DFE1E6 1.0pt; padding: 7.5pt 7.5pt 7.5pt 7.5pt;\">\n<p style=\"margin: 0cm 0cm 8pt; line-height: 107%; font-size: 11pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\">8.1.3 or newer<\/span><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" style=\"border: solid #DFE1E6 1.0pt; padding: 7.5pt 7.5pt 7.5pt 7.5pt;\">\n<p style=\"margin: 0cm 0cm 8pt; line-height: 107%; font-size: 11pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\"><a href=\"https:\/\/confluence.atlassian.com\/bitbucketserver\/bitbucket-data-center-and-server-8-2-release-notes-1130729887.html\" style=\"color: #0563c1; text-decoration: underline;\">Bitbucket Server and Data Center 8.2<\/a><\/span><\/p>\n<\/td>\n<td valign=\"top\" style=\"border: solid #DFE1E6 1.0pt; padding: 7.5pt 7.5pt 7.5pt 7.5pt;\">\n<p style=\"margin: 0cm 0cm 8pt; line-height: 107%; font-size: 11pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\">8.2.2 or newer<\/span><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" style=\"border: solid #DFE1E6 1.0pt; padding: 7.5pt 7.5pt 7.5pt 7.5pt;\">\n<p style=\"margin: 0cm 0cm 8pt; line-height: 107%; font-size: 11pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\"><a href=\"https:\/\/confluence.atlassian.com\/bitbucketserver\/bitbucket-data-center-and-server-8-3-release-notes-1141987753.html\" style=\"color: #0563c1; text-decoration: underline;\">Bitbucket Server and Data Center 8.3<\/a><\/span><\/p>\n<\/td>\n<td valign=\"top\" style=\"border: solid #DFE1E6 1.0pt; padding: 7.5pt 7.5pt 7.5pt 7.5pt;\">\n<p style=\"margin: 0cm 0cm 8pt; line-height: 107%; font-size: 11pt; font-family: Calibri, sans-serif;\"><span style=\"color: black;\">8.3.1 or newer<\/span><\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>You can download the latest version of&nbsp;Bitbucket from the&nbsp;<a href=\"https:\/\/www.atlassian.com\/software\/bitbucket\/download-archives\" target=\"_blank\">download center<\/a>. Visit <a href=\"https:\/\/confluence.atlassian.com\/kb\/faq-for-cve-2022-36804-1157481722.html\" target=\"_blank\">the Frequently Asked Questions (FAQ)<\/a>&nbsp;page if you have any questions.<\/p>\n<p>If, for any reason, you are unable to apply the security updates, you are advised to apply temporary partial mitigation by turning off public repositories by setting the option feature.public.access&nbsp;to false. This blocks unauthorized users from accessing the repository.<\/p>\n<p>If you access Bitbucket via a bitbucket.org domain, it is hosted by Atlassian and you are not affected by the vulnerability.<\/p>\n<h2>Vulnerability<\/h2>\n<p>The Remote Code Execution vulnerability was found by <a href=\"https:\/\/twitter.com\/TheGrandPew\" target=\"_blank\">Maxwell Garret<\/a> a security researcher at &nbsp;<a href=\"https:\/\/blog.assetnote.io\/2022\/09\/14\/rce-in-bitbucket-server\/\" target=\"_blank\">Assetnote<\/a> and assigned <a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2022-36804\" target=\"_blank\">CVE-2022-36804<\/a>. The vulnerability was rated as critical, which indicates a <a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2020\/05\/how-cvss-works-characterizing-and-scoring-vulnerabilities\">CVSS score<\/a> between 9 and 10 out of 10. If an attacker can read the content of a repository, either because it is a public repository or because they have read permission on a private repository, they are able to exploit the vulnerability.<\/p>\n<h2>Discovery<\/h2>\n<p>Bitbucket is a web based hosting service that distributes source code and development projects. Typically, Bitbucket Server is deployed on-premise and allows uploads of source code from GitHub and other platforms. Bitbucket uses git for many operations within the software. The discovery was inspired by the blog post from William Bowling about his <a href=\"https:\/\/devcraft.io\/2020\/10\/18\/github-rce-git-inject.html\" target=\"_blank\">RCE via git option injection in GitHub Enterprise<\/a>.<\/p>\n<h2>Exploitation<\/h2>\n<p>The proof-of-concept (PoC) exploit was made <a href=\"https:\/\/twitter.com\/TheGrandPew\/status\/1571847052962975745\" target=\"_blank\">public<\/a> on September 19, 2022. Attackers did not wait long. Some&nbsp;were&nbsp;<a href=\"https:\/\/twitter.com\/Balgan\/status\/1573363247239278594\" target=\"_blank\">observed scanning<\/a> for vulnerable instances as early as September 20th.<\/p>\n<p>Besides CISA adding the vulnerability to the known to be exploited vulnerabilities list, the Belgian federal cyber emergency team (CERT.be) warned that an exploit kit is now available for CVE-2022-36804 and urged users to patch.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">WARNING: An exploit kit is now available for CVE-2022-36804 affecting <a href=\"https:\/\/twitter.com\/Atlassian?ref_src=twsrc%5Etfw\">@Atlassian<\/a> <a href=\"https:\/\/twitter.com\/Bitbucket?ref_src=twsrc%5Etfw\">@Bitbucket<\/a> Server and Data Center. More information on <a href=\"https:\/\/t.co\/ccK9ng8j58\">https:\/\/t.co\/ccK9ng8j58<\/a> <br \/>If you haven&#8217;t done so already, it&#8217;s time to <a href=\"https:\/\/twitter.com\/hashtag\/patch?src=hash&amp;ref_src=twsrc%5Etfw\">#patch<\/a> <a href=\"https:\/\/twitter.com\/hashtag\/patch?src=hash&amp;ref_src=twsrc%5Etfw\">#patch<\/a> <a href=\"https:\/\/twitter.com\/hashtag\/patch?src=hash&amp;ref_src=twsrc%5Etfw\">#patch<\/a> <a href=\"https:\/\/t.co\/fytm6ZEGiw\">https:\/\/t.co\/fytm6ZEGiw<\/a><\/p>\n<p> &mdash; CERT.be (@certbe) <a href=\"https:\/\/twitter.com\/certbe\/status\/1574758255032680450?ref_src=twsrc%5Etfw\">September 27, 2022<\/a><\/p><\/blockquote>\n<p class=\"sample\"> <script async=\"\" src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script> <\/p>\n<p>Now that CISA has set a to-be-patched date of October 21, 2022 this will put the vulnerability higher on the agenda for US Federal Civilian Executive Branch Agencies (FCEB) agencies.&nbsp;As always,&nbsp;all other organizations are under advice to <a href=\"https:\/\/www.malwarebytes.com\/business\/vulnerability-patch-management\">patch<\/a> urgently if they haven&rsquo;t already.<\/p>\n<p><a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2022\/10\/warnings-about-actively-exploited-vulnerability-in-bitbucket-server-and-data-center\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<table cellpadding='10'>\n<tr>\n<td valign='top' align='left'>\n<p>Categories: <a href='https:\/\/www.malwarebytes.com\/blog\/category\/exploits-and-vulnerabilities' rel='category tag'>Exploits and vulnerabilities<\/a><\/p>\n<p>Categories: <a href='https:\/\/www.malwarebytes.com\/blog\/category\/news' rel='category tag'>News<\/a><\/p>\n<p>Tags: Atlassian<\/p>\n<p>Tags:  Bitbucket<\/p>\n<p>Tags:  git<\/p>\n<p>Tags:  CVE-2022-36804<\/p>\n<p>Tags:  RCE<\/p>\n<p>Tags:  read permission<\/p>\n<p>International cybersecurity authorities are warning about the active exploitation of a vulnerability in Bitbucket Server and Data Center<\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/www.malwarebytes.com\/blog\/news\/2022\/10\/warnings-about-actively-exploited-vulnerability-in-bitbucket-server-and-data-center' title='Actively exploited vulnerability in Bitbucket Server and Data Center'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel='nofollow' href='https:\/\/www.malwarebytes.com\/blog\/news\/2022\/10\/warnings-about-actively-exploited-vulnerability-in-bitbucket-server-and-data-center'>Actively exploited vulnerability in Bitbucket Server and Data Center<\/a> appeared first on <a rel='nofollow' href='https:\/\/www.malwarebytes.com'>Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[26411,25787,27625,22783,21738,32,18364,27626],"class_list":["post-20258","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-atlassian","tag-bitbucket","tag-cve-2022-36804","tag-exploits-and-vulnerabilities","tag-git","tag-news","tag-rce","tag-read-permission"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/20258","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=20258"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/20258\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=20258"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=20258"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=20258"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}