SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Atlassian Critical Vulnerabilities of November 2022 in Atlassian Crowd and Bitbucket Products is addressed. Patch Now!

Atlassian Critical Vulnerabilities of November 2022 in Atlassian Crowd and Bitbucket Products is addressed. Patch Now!

Atlassian released patches for two critical vulnerabilities of November 2022 affecting Bitbucket Server, Data Center, and Crowd products. Using a vulnerability management tool, these vulnerabilities are tracked as CVE-2022-43781 (Command Injection) and CVE-2022-43782 (Improper Authentication). A Vul...

Nov 20, 2022By Sonali3 min read

Atlassian released patches for two critical vulnerabilities of November 2022 affecting Bitbucket Server, Data Center, and Crowd products. Using a vulnerability management tool, these vulnerabilities are tracked as CVE-2022-43781 (Command Injection) and CVE-2022-43782 (Improper Authentication). A Vulnerability Management Software can prevent these attacks.

Technical Details of Atlassian Critical Vulnerabilities of November 2022:

CVE-2022-43781 – A Command Injection vulnerability is addressed in Atlassian Bitbucket Server and Data Center in environment variables. An attacker with permission to control their username can exploit this issue to gain code execution and execute code on the affected system.

CVE-2022-43782 – An Improper Authentication vulnerability is addressed in Atlassian Crowd in Crowd’s REST API under the user management path. This misconfiguration allows an attacker to connect remotely without providing a password and lets an attacker authenticate as the Crowd Application and call privileged endpoints. Adding the remote IP to an included list of allowed IPs can exploit the vulnerability, which deviates from the default settings.

Atlassian addresses these two critical vulnerabilities in this update.

Affected Versions of Atlassian Critical Vulnerabilities of November 2022:

Atlassian critical vulnerabilities of November 2022 are:

1.CVE-2022-43781:

  • Atlassian Bitbucket Server and Data Center from 7.0.0 before 7.6.19
  • Atlassian Bitbucket Server and Data Center from 7.7.0 before 7.17.12
  • Atlassian Bitbucket Server and Data Center from 7.18.0 before 7.21.6
  • Atlassian Bitbucket Server and Data Center from 8.0.0 before 8.0.5
  • Atlassian Bitbucket Server and Data Center from 8.1.0 before 8.1.5
  • Atlassian Bitbucket Server and Data Center from 8.2.0 before 8.2.4
  • Atlassian Bitbucket Server and Data Center from 8.3.0 before 8.3.3
  • Atlassian Bitbucket Server and Data Center from 8.4.0 before 8.4.2

“Note: 8.x version series is only affected if “mesh.enabled” is set to false in “bitbucket.properties”.”

2.CVE-2022-43782:

  • Atlassian Crowd from 3.0.0 before 4.4.4
  • Atlassian Crowd from 5.0.0 before 5.0.3

“Note: 3.0.0 has reached EOL and hence no version is published to fix the issue in this range.”

Solution

The solution for Atlassian critical vulnerabilities of November 2022 are:

1.CVE-2022-43781:

A definite version is released for the product. 7.6.19, 7.17.12, 7.21.6, 8.0.5, 8.1.5, 8.2.4, 8.3.3, 8.4.2, 8.5.0 or later are fixed versions.

2.CVE-2022-43782:

This issue is resolving with the help of Version 4.4.4 and 5.0.3

Mitigation

Some mitigation advice for Atlassian critical vulnerabilities of November 2022:

  1. CVE-2022-43781:

If you cannot upgrade the Bitbucket instance, disable “Public Signup.” This will reduce the risk of exploitation by changing the attack vector from an unauthenticated attack to an authenticated one.

To disable this setting:

  • Go to Administration > Authentication.
  • Clear the Allow public sign-up checkbox.

“Note : This is a temporary mitigation measure as ADMIN or SYS_ADMIN authenticated users still have the ability to exploit the vulnerability when public signup is disabled. Therefore, it is recommended to upgrade to a fixed version as soon as possible.”

These two critical vulnerabilities are the main focus of the Atlassian patch update.

2. CVE-2022-43782:

If you are unable to update the crowd, ensure that you do not configure the crowd application for remote access,

Follow these steps to get a similar result:

  • Log in to the Crowd Administration Console.
  • In the top navigation bar, click Applications.
  • In the Application Browser, click the application name you wish to update.
  • In the View Application screen, click the Remote Addresses tab. You will see a list of IP addresses and hostnames currently mapped to the application.
  • Remove any remote addresses accordingly.

If a remote IP is necessary, set a strong password for your crowd application. These were the highlights of Atlassian critical vulnerabilities of November 2022.

SanerNow Network Scanner detects these vulnerabilities. Use SanerNow and keep your systems updated and secure.

Featured Posts

Open CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials
CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials

CVE Research

CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials

Sep 25, 2026

Open Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions
Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions

CVE Research

Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions

Two MikroTik RouterOS CVEs entered CISA KEV seven days after production fixes. Dated reporting places SSH-chain exploitation involving CVE-2026-86060 at least one calendar day before those releases; no comparable start date is established for CVE-2026-67277.

Sep 25, 2026

Open Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch
Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch

CVE Research

Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch

Four vulnerabilities added to CISA’s KEV catalog on September 9, 2026 show widely different timelines between public disclosure and formal exploitation-based prioritization, ranging from one day to 239 days.

Sep 24, 2026

Open TA412/APT31: Mapping Threat Actor Patterns to CVE Exploitation Chains

TA412/APT31: Mapping Threat Actor Patterns to CVE Exploitation Chains

CVE Research

TA412/APT31: Mapping Threat Actor Patterns to CVE Exploitation Chains

A chronological look at how a long-running China-nexus espionage cluster evolved from server-side exploitation to a chained Chrome/Windows zero-day kit — and what that shift signals.

Sep 24, 2026