A critical remote code execution flaw, CVE-2022-36804, affected Atlassian Bitbucket Server and Data Center by allowing user-controlled input to reach underlying Git commands. Researchers showed that a NULL byte injection issue in Java-to-native process execution could let attackers smuggle extra Git options such as --exec, turning repository API requests into arbitrary command execution on Linux systems. Another reported exploitation path used Git functionality to write a JSP file to the server, providing a route to persistent code execution.
Security monitoring later recorded active attacks against exposed Bitbucket instances through multiple API endpoints, following the release of public exploit code. Observed malicious requests targeted repositories with crafted parameters designed to trigger command injection, and defenders were urged to upgrade to Atlassian's fixed versions. Mitigations included Bitbucket-side validation for NULL characters and hardening in the underlying NuProcess library, though the case also highlighted the broader risk of option injection in command-execution features even without NULL bytes.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
MBSD-SOC reported that it started seeing attacks targeting CVE-2022-36804 against Atlassian Bitbucket Server and Data Center. The observed requests targeted the archive endpoint and used a malicious prefix parameter to inject Git options.
Public exploit code for the Bitbucket Server and Data Center vulnerability CVE-2022-36804 was released, increasing the likelihood of broader exploitation. MBSD-SOC later cited this release as a factor that could drive more attacks.
Atlassian released fixes for CVE-2022-36804 in August 2022 for Bitbucket Server and Data Center. The flaw allowed remote command execution through Bitbucket's handling of Git command arguments.
NuProcess introduced NULL-byte validation in version 2.0.5 following the Bitbucket vulnerability disclosure. The MBSD analysis recommends upgrading to version 2.0.5 or later.
After disclosure of CVE-2022-36804, a Bitbucket engineer submitted a pull request to the NuProcess library to add NULL-byte validation. This was intended to prevent the Java-to-native argument handling issue that enabled the vulnerability.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.