Vulnerability Details CVE-2019-3397
Atlassian Bitbucket Data Center licensed instances starting with version 5.13.0 before 5.13.6 (the fixed version for 5.13.x), from 5.14.0 before 5.14.4 (fixed version for 5.14.x), from 5.15.0 before 5.15.3 (fixed version for 5.15.x), from 5.16.0 before 5.16.3 (fixed version for 5.16.x), from 6.0.0 before 6.0.3 (fixed version for 6.0.x), and from 6.1.0 before 6.1.2 (the fixed version for 6.1.x) allow remote attackers who have admin permissions to achieve remote code execution on a Bitbucket server instance via path traversal through the Data Center migration tool.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.168
EPSS Ranking 94.7%
CVSS Severity
CVSS v3 Score 9.1
CVSS v2 Score 9.0
Products affected by CVE-2019-3397
-
cpe:2.3:a:atlassian:bitbucket:5.13.0
-
cpe:2.3:a:atlassian:bitbucket:5.13.1
-
cpe:2.3:a:atlassian:bitbucket:5.13.2
-
cpe:2.3:a:atlassian:bitbucket:5.13.3
-
cpe:2.3:a:atlassian:bitbucket:5.13.4
-
cpe:2.3:a:atlassian:bitbucket:5.13.5
-
cpe:2.3:a:atlassian:bitbucket:5.14.0
-
cpe:2.3:a:atlassian:bitbucket:5.14.1
-
cpe:2.3:a:atlassian:bitbucket:5.14.2
-
cpe:2.3:a:atlassian:bitbucket:5.14.3
-
cpe:2.3:a:atlassian:bitbucket:5.15.0
-
cpe:2.3:a:atlassian:bitbucket:5.15.1
-
cpe:2.3:a:atlassian:bitbucket:5.15.2
-
cpe:2.3:a:atlassian:bitbucket:5.16.0
-
cpe:2.3:a:atlassian:bitbucket:5.16.1
-
cpe:2.3:a:atlassian:bitbucket:5.16.2
-
cpe:2.3:a:atlassian:bitbucket:6.0.0
-
cpe:2.3:a:atlassian:bitbucket:6.0.1
-
cpe:2.3:a:atlassian:bitbucket:6.0.2
-
cpe:2.3:a:atlassian:bitbucket:6.1.0
-
cpe:2.3:a:atlassian:bitbucket:6.1.1