CVE-2022-36804 is a pre-authentication remote code execution vulnerability in Atlassian Bitbucket Server and Data Center archive-related API handling. A user-controlled archive-prefix value was passed to a Git invocation through NuProcess. Embedded null characters were not rejected before the Java-to-native process boundary, allowing a single supplied argument to be split into unintended command-line arguments. An attacker could inject Git archive options, including options that cause Git to invoke a command, resulting in operating-system command execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
10 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository is a small Python proof-of-concept exploit for CVE-2022-36804 affecting Atlassian Bitbucket Server/Data Center. The repo contains only three files: LICENSE, README.md, and main.py. The only code file, main.py, is the clear entry point and implements the exploit logic directly. Although the README says the repo is part of the 'hgrab-framework', the code itself is a standalone Python script rather than a recognized exploit framework module. It accepts two command-line arguments: a file containing target base URLs and a command to execute. For each target, it spawns a thread and performs an unauthenticated GET request to /rest/api/latest/repos to enumerate repositories. If at least one public repository is found, it builds a second malicious request to the Bitbucket archive endpoint for that repository. The exploit injects a command into the query string using a crafted prefix parameter containing null bytes and an --exec option, attempting to achieve remote command execution. The script does not capture command output or establish an interactive shell. Instead, it treats an HTTP 500 response as a success indicator and prints a success message. This makes it an operational but basic exploit: it performs real exploitation attempts with an operator-controlled command payload, but has limited post-exploitation handling and minimal error reporting. It is not merely a detector, because it actively sends the malicious request intended to trigger code execution.
Repository is a small, lab-focused proof-of-concept exploit for CVE-2022-36804 (Atlassian Bitbucket Server/Data Center pre-auth RCE via null-byte argument injection into git archive). Structure: - exploit.sh: Main exploit script. Takes 5 args (target_ip, project_key, repo_slug, attacker_ip, attacker_port), builds a URL to Bitbucket’s /rest/api/latest/.../archive endpoint, injects %00 null bytes into the prefix parameter to break argument parsing and add git arguments (notably --exec=/bin/bash -c '<reverse shell>'), and sends the request with curl. Uses 'Host: localhost' header as a workaround for Tomcat host header validation in the provided lab setup. - docker-compose.yml: Two-container lab: a vulnerable Bitbucket Server 7.17.1 victim (bitbucket-victim) exposed on port 7990, and a Kali attacker container built from the Dockerfile, both on an isolated bridge network. - Dockerfile: Builds the attacker container with tools needed to run the exploit and catch shells (git, curl, netcat-traditional, python3, nano). - README.md: Long-form technical explanation of the vulnerability mechanics (NuProcess + execve null-byte truncation leading to git argument injection), lab setup instructions, and references. Overall capability: unauthenticated (when public repos are enabled) network-based RCE against vulnerable Bitbucket via a single crafted HTTP request, resulting in a bash reverse shell to an attacker-controlled listener.
This repository contains a Python exploit for CVE-2022-36804, a remote command execution (RCE) vulnerability in Atlassian Bitbucket Server and Data Center. The exploit targets several vulnerable versions (7.6, 7.17, 7.21, 8.0, 8.1, 8.2, 8.3) prior to their respective patched releases. The main exploit logic is in 'main.py', which takes a list of target Bitbucket server URLs and a command to execute. For each target, it enumerates public repositories and attempts to exploit the archive endpoint using a crafted URL that injects the user-supplied command. If successful, the exploit reports command execution on the target. The README provides usage instructions and affected product versions. The exploit is operational, requiring the attacker to supply a command and a list of targets, and is not part of a larger exploitation framework. The main attack vector is network-based, exploiting Bitbucket's HTTP API endpoints. No hardcoded IPs or domains are present; targets are user-supplied.
This repository contains a single Metasploit module: 'bitbucket_git_cmd_injection.rb', which exploits CVE-2022-36804, a command injection vulnerability in Atlassian Bitbucket Server and Data Center. The exploit targets the '/rest/api/latest/projects/{projectKey}/repos/{repositorySlug}/archive' API endpoint, which is vulnerable to unauthenticated command injection via crafted parameters containing NULL bytes. The module supports both unauthenticated and authenticated exploitation, depending on repository visibility and provided credentials. It can deploy either a staged Linux Meterpreter reverse shell or a simple Unix reverse bash shell, depending on the selected target. The module includes logic to check the target's version, authenticate if credentials are provided, enumerate repositories, and execute arbitrary commands or payloads. The attack vector is network-based, and the main fingerprintable endpoint is the vulnerable Bitbucket API path. The code is weaponized, as it is part of the Metasploit framework and supports customizable payloads.
This repository provides a working exploit for CVE-2022-36804, a critical command injection vulnerability in Atlassian Bitbucket Server and Data Center. The exploit is implemented as a Python script (cve-2022-36804.py) that targets vulnerable Bitbucket REST API endpoints, allowing an attacker with at least read access to a repository to execute arbitrary system commands on the server. The script can be used to run any command, including spawning a reverse shell to the attacker's machine. The included Dockerfile allows users to build a vulnerable Bitbucket instance for testing. The README.md provides detailed usage instructions, including how to set up the test environment, identify the target, and execute the exploit. The main attack vector is network-based, leveraging HTTP requests to the Bitbucket REST API. The exploit is operational and can be used to gain remote code execution on affected Bitbucket servers.
This repository provides a Python-based exploit for CVE-2022-36804, a critical unauthenticated command injection vulnerability in Atlassian Bitbucket Server and Data Center versions prior to 8.3.1. The exploit allows attackers to execute arbitrary commands on the target server, including spawning a reverse shell to an attacker-controlled host. The main script (main.py) supports both single-target and mass exploitation modes, with options for automatic repository detection, custom command execution, and reverse shell payloads. It can use a session cookie to target private repositories. The exploit interacts with Bitbucket's REST API endpoints to enumerate repositories, check for vulnerability, and trigger the command injection. The repository includes a requirements.txt for dependencies and a README.md with usage instructions and references. The attack vector is network-based, targeting exposed Bitbucket HTTP(S) endpoints. No hardcoded IPs or domains are present, but the exploit constructs requests to user-supplied Bitbucket server URLs.
This repository is a proof-of-concept exploit for CVE-2022-36804, a critical unauthenticated command injection vulnerability in Atlassian Bitbucket Server and Data Center (<8.3.1). The main exploit logic is implemented in 'main.py', which is a Python script that automates the process of discovering open repositories on a target Bitbucket instance, checking for vulnerability, and exploiting the command injection flaw. The exploit works by sending crafted HTTP GET requests to Bitbucket's REST API endpoints, injecting arbitrary shell commands into the 'archive' endpoint. The script supports both unauthenticated exploitation (if public repos are enabled) and authenticated exploitation (using a provided BITBUCKETSESSIONID cookie for private repos). The output of executed commands is not reliably returned, so the author recommends using out-of-band exfiltration techniques. The repository also includes a README with usage instructions and references, and a requirements.txt listing Python dependencies. No hardcoded IPs or domains are present; the target server is specified by the user at runtime.
This repository provides a working exploit for CVE-2022-36804, a critical pre-auth remote code execution (RCE) vulnerability in Atlassian Bitbucket Server and Data Center. The repository contains three files: a Dockerfile for setting up a vulnerable Bitbucket instance (version 7.17.1), a README.md with detailed usage instructions and background, and the main exploit script (cve-2022-36804.py). The Python script allows an attacker to execute arbitrary system commands on a vulnerable Bitbucket server by exploiting a command injection flaw in the REST API endpoint for repository archives. The exploit can be used to run commands such as 'id', 'whoami', or to spawn a reverse shell to an attacker-controlled host. The script supports targeting both public and private repositories (the latter requiring a valid session cookie). The attack vector is network-based, requiring only HTTP access to the vulnerable server. The repository is operational and provides all necessary components for successful exploitation, including payload customization and reverse shell techniques.
This repository provides a Python-based operational exploit for CVE-2022-36804, a critical unauthenticated command injection vulnerability in Atlassian Bitbucket Server and Data Center (<8.3.1). The main exploit logic is in 'main.py', which supports both single-target and mass exploitation modes. The script can automatically enumerate public repositories on a target Bitbucket instance, check for vulnerability, and exploit the command injection via a crafted HTTP request to the '/rest/api/latest/projects/{project}/repos/{repo}/archive' endpoint. The exploit can execute arbitrary commands or spawn a reverse shell to an attacker-controlled host. It supports the use of a session cookie for attacking private repositories. The repository also includes a 'requirements.txt' for dependencies and a detailed 'README.md' with usage instructions and references. The attack vector is network-based, targeting Bitbucket's REST API endpoints. No hardcoded IPs or domains are present, but the exploit constructs fingerprintable API paths for exploitation.
This repository contains a proof-of-concept exploit for CVE-2022-36804, a remote code execution vulnerability in Atlassian Bitbucket Server and Data Center versions prior to 8.3.1. The exploit is implemented in Python (exploit.py) and allows an attacker with access to a repository (public or with credentials for private repos) to execute arbitrary commands on the target server by abusing the Bitbucket REST API's archive endpoint. The script supports both vulnerability checking and command execution, with the ability to use a proxy and session cookies for private repositories. The README provides usage instructions and example payloads, including a reverse shell. The main attack vector is network-based, targeting the Bitbucket REST API over HTTP(S). The repository is structured simply, with a single exploit script and a detailed README.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical pre-authentication remote command execution vulnerability in Atlassian Bitbucket Server and Data Center caused by null-byte argument injection into Git command invocation via the archive API's prefix parameter.
Atlassian Bitbucket Server and Data Center の複数APIエンドポイントに存在するコマンドインジェクション脆弱性で、細工された不正リクエストにより任意コード実行につながる。本文では実際の攻撃観測と公開済みエクスプロイトコードに言及している。
A remote command execution vulnerability in Bitbucket caused by improper handling of NULL bytes in arguments passed to git commands, allowing attackers to inject command options such as git archive --exec and achieve code execution.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.