Answer in brief
CVE-2022-36804 records a High severity vulnerability in CVE Program Container. The current sources mark it as known exploited. The current feed maps Atlassian/Bitbucket Data Center (generic), Atlassian/Bitbucket Server (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Atlassian/Bitbucket Data Center (generic), Atlassian/Bitbucket Server (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Atlassian/Bitbucket Data Centergeneric | >=7.0.0 <unspecified || >=unspecified <7.6.17 || >=7.7.0 <unspecified || >=unspecified <7.17.10 || >=7.18.0 <unspecified || >=unspecified <7.21.4 || >=8.0.0 <unspecified || >=unspecified <8.0.3 || >=8.1.0 <unspecified || >=unspecified <8.1.3 || >=8.2.0 <unspecified || >=unspecified <8.2.2 || >=8.3.0 <unspecified || >=unspecified <8.3.1 | unspecified, 7.6.17, 7.17.10, 7.21.4, 8.0.3, 8.1.3, 8.2.2, 8.3.1 |
| Atlassian/Bitbucket Servergeneric | >=7.0.0 <unspecified || >=unspecified <7.6.17 || >=7.7.0 <unspecified || >=unspecified <7.17.10 || >=7.18.0 <unspecified || >=unspecified <7.21.4 || >=8.0.0 <unspecified || >=unspecified <8.0.3 || >=8.1.0 <unspecified || >=unspecified <8.1.3 || >=8.2.0 <unspecified || >=unspecified <8.2.2 || >=8.3.0 <unspecified || >=unspecified <8.3.1 | unspecified, 7.6.17, 7.17.10, 7.21.4, 8.0.3, 8.1.3, 8.2.2, 8.3.1 |
Published upstream
Aug 25, 2022
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 21, 2025
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
May 24, 2026
Added to CISA KEV
Sep 30, 2022
Evidence: source:kev:kev:kev:recordMultiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21.4, from version 8.0.0 before version 8.0.3, from version 8.1.0 before version 8.1.3, and from version 8.2.0 before version 8.2.2, and from version 8.3.0 before 8.3.1 allows remote attackers with read permissions to a public or private Bitbucket repository to execute arbitrary code by sending a malicious HTTP request. This vulnerability was reported via our Bug Bounty Program by TheGrandPew.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2022-36804 records a High severity vulnerability in CVE Program Container. The current sources mark it as known exploited. The current feed maps Atlassian/Bitbucket Data Center (generic), Atlassian/Bitbucket Server (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Atlassian/Bitbucket Data Center (generic), Atlassian/Bitbucket Server (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Atlassian/Bitbucket Data Centergeneric | >=7.0.0 <unspecified || >=unspecified <7.6.17 || >=7.7.0 <unspecified || >=unspecified <7.17.10 || >=7.18.0 <unspecified || >=unspecified <7.21.4 || >=8.0.0 <unspecified || >=unspecified <8.0.3 || >=8.1.0 <unspecified || >=unspecified <8.1.3 || >=8.2.0 <unspecified || >=unspecified <8.2.2 || >=8.3.0 <unspecified || >=unspecified <8.3.1 | unspecified, 7.6.17, 7.17.10, 7.21.4, 8.0.3, 8.1.3, 8.2.2, 8.3.1 |
| Atlassian/Bitbucket Servergeneric | >=7.0.0 <unspecified || >=unspecified <7.6.17 || >=7.7.0 <unspecified || >=unspecified <7.17.10 || >=7.18.0 <unspecified || >=unspecified <7.21.4 || >=8.0.0 <unspecified || >=unspecified <8.0.3 || >=8.1.0 <unspecified || >=unspecified <8.1.3 || >=8.2.0 <unspecified || >=unspecified <8.2.2 || >=8.3.0 <unspecified || >=unspecified <8.3.1 | unspecified, 7.6.17, 7.17.10, 7.21.4, 8.0.3, 8.1.3, 8.2.2, 8.3.1 |
Published upstream
Aug 25, 2022
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 21, 2025
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
May 24, 2026
Added to CISA KEV
Sep 30, 2022
Evidence: source:kev:kev:kev:recordMultiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21.4, from version 8.0.0 before version 8.0.3, from version 8.1.0 before version 8.1.3, and from version 8.2.0 before version 8.2.2, and from version 8.3.0 before 8.3.1 allows remote attackers with read permissions to a public or private Bitbucket repository to execute arbitrary code by sending a malicious HTTP request. This vulnerability was reported via our Bug Bounty Program by TheGrandPew.
Quoted source text, attributed separately from HOL analysis.