← Vulnerability feed

Vulnerability record · CVE-2019-3397 · published 3 June 2019

CVE-2019-3397: Atlassian bitbucket path traversal vulnerability

Atlassian · Bitbucket

Atlassian Bitbucket Data Center licensed instances starting with version 5.13.0 before 5.13.6 (the fixed version for 5.13.x), from 5.14.0 before 5.14.4 (fixed version for 5.14.x), from 5.15.0 before 5.15.3 (fixed version for 5.15.x), from 5.16.0 before 5.16.3 (fixed version for 5.16.x), from 6.0.0 before 6.0.3 (fixed version for 6.0.x), and from 6.1.0 before 6.1.2 (the fixed version for 6.1.x) allow remote attackers who have admin permissions to achieve remote code execution on a Bitbucket server instance via path traversal through the Data Center migration tool.

9.1 CVSS 3.0 Critical EPSS 4.4% · top 9.0% CWE-22 · Path traversal
9.1CVSS 3.0 base score, v2 9.0
4.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Atlassian Bitbucket Data Center licensed instances starting with version 5.13.0 before 5.13.6 (the fixed version for 5.13.x), from 5.14.0 before 5.14.4 (fixed version for 5.14.x), from 5.15.0 before 5.15.3 (fixed version for 5.15.x), from 5.16.0 before 5.16.3 (fixed version for 5.16.x), from 6.0.0 before 6.0.3 (fixed version for 6.0.x), and from 6.1.0 before 6.1.2 (the fixed version for 6.1.x) allow remote attackers who have admin permissions to achieve remote code execution on a Bitbucket server instance via path traversal through the Data Center migration tool.

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://jira.atlassian.com/browse/BSERV-11706 MitigationVendor Advisory
https://jira.atlassian.com/browse/BSERV-11706 MitigationVendor Advisory

Track CVE-2019-3397 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2022-36804Atlassian Bitbucket Server and Data Center API command injectionMultiple API endpoints in Atlassian Bitbucket Server and Data Center fail to properly neutralize command and argument input, allowing OS command inje…KEVEPSS 99%analysed9.9CVE-2018-5225Atlassian bitbucket link following vulnerabilityIn browser editing in Atlassian Bitbucket Server from version 4.13.0 before 5.4.8 (the fixed version for 4.13.0 through 5.4.7), 5.5.0 before 5.5.8 (t…EPSS 3.4%9.8CVE-2022-43781Bitbucket Server and Data Center command injection via environment variablesBitbucket Server and Data Center contains a command injection flaw (CWE-77) reachable through environment variables. An attacker who can control thei…EPSS 98%analysed9.8CVE-2022-26136Atlassian bamboo improper authentication vulnerabilityA vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps…EPSS 5.4%9.8CVE-2019-15000Atlassian bitbucket os command injection vulnerabilityThe commit diff rest endpoint in Bitbucket Server and Data Center before 5.16.10 (the fixed version for 5.16.x ), from 6.0.0 before 6.0.10 (the fixed…EPSS 7.8%8.8CVE-2022-26137Atlassian bamboo origin validation error vulnerabilityA vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the a…EPSS 2.3%8.8CVE-2019-15010Atlassian bitbucket command injection vulnerabilityBitbucket Server and Bitbucket Data Center versions starting from version 3.0.0 before version 5.16.11, from version 6.0.0 before 6.0.11, from versio…EPSS 2.6%8.8CVE-2019-15012Atlassian bitbucket improper privilege management vulnerabilityBitbucket Server and Bitbucket Data Center from version 4.13. before 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.1.9, from…EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2019-3397), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.