SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Atlassian Critical Vulnerabilities of November 2022 in Atlassian Crowd and Bitbucket Products is addressed. Patch Now!

Atlassian Critical Vulnerabilities of November 2022 in Atlassian Crowd and Bitbucket Products is addressed. Patch Now!

Atlassian released patches for two critical vulnerabilities of November 2022 affecting Bitbucket Server, Data Center, and Crowd products. Using a vulnerability management tool, these vulnerabilities are tracked as CVE-2022-43781 (Command Injection) and CVE-2022-43782 (Improper Authentication). A Vul...

Nov 20, 2022By Sonali3 min read

Atlassian released patches for two critical vulnerabilities of November 2022 affecting Bitbucket Server, Data Center, and Crowd products. Using a vulnerability management tool, these vulnerabilities are tracked as CVE-2022-43781 (Command Injection) and CVE-2022-43782 (Improper Authentication). A Vulnerability Management Software can prevent these attacks.

Technical Details of Atlassian Critical Vulnerabilities of November 2022:

CVE-2022-43781 – A Command Injection vulnerability is addressed in Atlassian Bitbucket Server and Data Center in environment variables. An attacker with permission to control their username can exploit this issue to gain code execution and execute code on the affected system.

CVE-2022-43782 – An Improper Authentication vulnerability is addressed in Atlassian Crowd in Crowd’s REST API under the user management path. This misconfiguration allows an attacker to connect remotely without providing a password and lets an attacker authenticate as the Crowd Application and call privileged endpoints. Adding the remote IP to an included list of allowed IPs can exploit the vulnerability, which deviates from the default settings.

Atlassian addresses these two critical vulnerabilities in this update.

Affected Versions of Atlassian Critical Vulnerabilities of November 2022:

Atlassian critical vulnerabilities of November 2022 are:

1.CVE-2022-43781:

  • Atlassian Bitbucket Server and Data Center from 7.0.0 before 7.6.19
  • Atlassian Bitbucket Server and Data Center from 7.7.0 before 7.17.12
  • Atlassian Bitbucket Server and Data Center from 7.18.0 before 7.21.6
  • Atlassian Bitbucket Server and Data Center from 8.0.0 before 8.0.5
  • Atlassian Bitbucket Server and Data Center from 8.1.0 before 8.1.5
  • Atlassian Bitbucket Server and Data Center from 8.2.0 before 8.2.4
  • Atlassian Bitbucket Server and Data Center from 8.3.0 before 8.3.3
  • Atlassian Bitbucket Server and Data Center from 8.4.0 before 8.4.2

Note: 8.x version series is only affected if “mesh.enabled” is set to false in “bitbucket.properties”.

2.CVE-2022-43782:

  • Atlassian Crowd from 3.0.0 before 4.4.4
  • Atlassian Crowd from 5.0.0 before 5.0.3

Note: 3.0.0 has reached EOL and hence no version is published to fix the issue in this range.

Solution

The solution for Atlassian critical vulnerabilities of November 2022 are:

1.CVE-2022-43781:

A definite version is released for the product. 7.6.19, 7.17.12, 7.21.6, 8.0.5, 8.1.5, 8.2.4, 8.3.3, 8.4.2, 8.5.0 or later are fixed versions.

2.CVE-2022-43782:

This issue is resolving with the help of Version 4.4.4 and 5.0.3

Mitigation

Some mitigation advice for Atlassian critical vulnerabilities of November 2022:

  1. CVE-2022-43781:

If you cannot upgrade the Bitbucket instance, disable “Public Signup.” This will reduce the risk of exploitation by changing the attack vector from an unauthenticated attack to an authenticated one.

To disable this setting:

  • Go to Administration > Authentication.
  • Clear the Allow public sign-up checkbox.

Note : This is a temporary mitigation measure as ADMIN or SYS_ADMIN authenticated users still have the ability to exploit the vulnerability when public signup is disabled. Therefore, it is recommended to upgrade to a fixed version as soon as possible.

These two critical vulnerabilities are the main focus of the Atlassian patch update.

2. CVE-2022-43782:

If you are unable to update the crowd, ensure that you do not configure the crowd application for remote access,

Follow these steps to get a similar result:

  • Log in to the Crowd Administration Console.
  • In the top navigation bar, click Applications.
  • In the Application Browser, click the application name you wish to update.
  • In the View Application screen, click the Remote Addresses tab. You will see a list of IP addresses and hostnames currently mapped to the application.
  • Remove any remote addresses accordingly.

If a remote IP is necessary, set a strong password for your crowd application. These were the highlights of Atlassian critical vulnerabilities of November 2022.

SanerNow Network Scanner detects these vulnerabilities. Use SanerNow and keep your systems updated and secure.

Featured Posts

Open CVE-2026-31431: From 732 Bytes to Root - Anatomy of a Modern Linux Privilege Escalation

CVE-2026-31431: From 732 Bytes to Root - Anatomy of a Modern Linux Privilege Escalation

CVE Research

CVE-2026-31431: From 732 Bytes to Root - Anatomy of a Modern Linux Privilege Escalation

Jun 24, 2026

Open CVE-2026-31431: The Nine-Year Kernel Bug Hiding in Plain Sight

CVE-2026-31431: The Nine-Year Kernel Bug Hiding in Plain Sight

CVE Research

CVE-2026-31431: The Nine-Year Kernel Bug Hiding in Plain Sight

Jun 23, 2026

Open Squidbleed: A 29-Year-Old Squid Proxy Flaw That Leaks Cleartext HTTP Requests
Squidbleed: A 29-Year-Old Squid Proxy Flaw That Leaks Cleartext HTTP Requests

CVE Research

Squidbleed: A 29-Year-Old Squid Proxy Flaw That Leaks Cleartext HTTP Requests

Jun 23, 2026

Open AryStinger Malware Leverages 4,300+ Legacy Routers to Establish Persistent Spy Infrastructure
AryStinger Malware Leverages 4,300+ Legacy Routers to Establish Persistent Spy Infrastructure

CVE Research

AryStinger Malware Leverages 4,300+ Legacy Routers to Establish Persistent Spy Infrastructure

AryStinger represents a calculated shift in IoT threat methodology, abandoning noisy, destructive payloads in favor of silent, long-term reconnaissance infrastructure. By exploiting unpatched, end-of-life routers and NAS devices through decade-old vulnerabilities, the threat operator has assembled a distributed fleet of over 4,300 Executor nodes capable of conducting parallelized DNS enumeration, port scanning, and service fingerprinting at scale, all while masking origin behind residential IP addresses. With active development ongoing and a potential operational timeline stretching back to 2024, AryStinger underscores a growing and underappreciated risk: forgotten edge hardware is not merely a compliance gap but exploitable infrastructure.

Jun 23, 2026

Atlassian Critical Vulnerabilities of November 2022 in Atlassian Crowd | SecPod