Vulnerability Description
Atlassian Bitbucket Data Center licensed instances starting with version 5.13.0 before 5.13.6 (the fixed version for 5.13.x), from 5.14.0 before 5.14.4 (fixed version for 5.14.x), from 5.15.0 before 5.15.3 (fixed version for 5.15.x), from 5.16.0 before 5.16.3 (fixed version for 5.16.x), from 6.0.0 before 6.0.3 (fixed version for 6.0.x), and from 6.1.0 before 6.1.2 (the fixed version for 6.1.x) allow remote attackers who have admin permissions to achieve remote code execution on a Bitbucket server instance via path traversal through the Data Center migration tool.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Atlassian | Bitbucket | >= 5.13.0, < 5.13.6 |
Related Weaknesses (CWE)
References
- https://jira.atlassian.com/browse/BSERV-11706MitigationVendor Advisory
- https://jira.atlassian.com/browse/BSERV-11706MitigationVendor Advisory
FAQ
What is CVE-2019-3397?
CVE-2019-3397 is a vulnerability with a CVSS score of 9.1 (CRITICAL). Atlassian Bitbucket Data Center licensed instances starting with version 5.13.0 before 5.13.6 (the fixed version for 5.13.x), from 5.14.0 before 5.14.4 (fixed version for 5.14.x), from 5.15.0 before 5...
How severe is CVE-2019-3397?
CVE-2019-3397 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-3397?
Check the references section above for vendor advisories and patch information. Affected products include: Atlassian Bitbucket.