CVE-2019-3397: Atlassian Bitbucket

Critical severity, CVSS 9.1. EPSS: 4.4% chance of exploitation in the next 30 days.

Atlassian Bitbucket Data Center licensed instances starting with version 5.13.0 before 5.13.6 (the fixed version for 5.13.x), from 5.14.0 before 5.14.4 (fixed version for 5.14.x), from 5.15.0 before 5.15.3 (fixed version for 5.15.x), from 5.16.0 before 5.16.3 (fixed version for 5.16.x), from 6.0.0 before 6.0.3 (fixed version for 6.0.x), and from 6.1.0 before 6.1.2 (the fixed version for 6.1.x) allow remote attackers who have admin permissions to achieve remote code execution on a Bitbucket server instance via path traversal through the Data Center migration tool.

Affected products

  • Atlassian Bitbucket: from 5.13.0, before 5.13.6 (fixed in 5.13.6); from 5.14.0, before 5.14.4 (fixed in 5.14.4); from 5.15.0, before 5.15.3 (fixed in 5.15.3); from 5.16.0, before 5.16.3 (fixed in 5.16.3); from 6.0.0, before 6.0.3 (fixed in 6.0.3); from 6.1.0, before 6.1.2 (fixed in 6.1.2)

Published 2019-06-03. Last modified 2026-06-17.