Atlassian Bitbucket Data Center licensed instances starting with version 5.13.0 before 5.13.6 (the fixed version for 5.13.x), from 5.14.0 before 5.14.4 (fixed version for 5.14.x), from 5.15.0 before 5.15.3 (fixed version for 5.15.x), from 5.16.0 before 5.16.3 (fixed version for 5.16.x), from 6.0.0 before 6.0.3 (fixed version for 6.0.x), and from 6.1.0 before 6.1.2 (the fixed version for 6.1.x) allow remote attackers who have admin permissions to achieve remote code execution on a Bitbucket server instance via path traversal through the Data Center migration tool.
Vector
NETWORK
Complexity
LOW
Authentication
SINGLE_INSTANCE
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE
Atlassian Bitbucket 5.13.0 (not an official CPE)
Atlassian Bitbucket 5.13.1 (not an official CPE)
Atlassian Bitbucket 5.13.2 (not an official CPE)
Atlassian Bitbucket 5.13.3 (not an official CPE)
Atlassian Bitbucket 5.13.4 (not an official CPE)
Atlassian Bitbucket 5.14.0 (not an official CPE)
Atlassian Bitbucket 5.14.1 (not an official CPE)
Atlassian Bitbucket 5.14.2 (not an official CPE)
Atlassian Bitbucket 5.15.0 (not an official CPE)
Atlassian Bitbucket 5.15.1 (not an official CPE)
Atlassian Bitbucket 5.16.0 (not an official CPE)
Advisory | Patch | Confirmed | Link |
---|---|---|---|
https://jira.atlassian.com/browse/BSERV-11706 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (ID 22)
Related CAPEC 7
Relative Path Traversal (CAPEC-ID 139)
Directory Traversal (CAPEC-ID 213)
File System Function Injection, Content Based (CAPEC-ID 23)
Using Slashes and URL Encoding Combined to Bypass Validation Logic (CAPEC-ID 64)
Manipulating Input to File System Calls (CAPEC-ID 76)
Using Escaped Slashes in Alternate Encoding (CAPEC-ID 78)
Using Slashes in Alternate Encoding (CAPEC-ID 79)