Bitbucket version 7.0.0 suffers from a remote command execution vulnerability.
abac6940dc4a2ee511a0471c9fd076aab1d296308b184e71e03da3ce0d1cc8f9
Various versions of Bitbucket Server and Data Center are vulnerable to an unauthenticated command injection vulnerability in multiple API endpoints. The /rest/api/latest/projects/{projectKey}/repos/{repositorySlug}/archive endpoint creates an archive of the repository, leveraging the git-archive command to do so. Supplying NULL bytes to the request enables the passing of additional arguments to the command, ultimately enabling execution of arbitrary commands.
b243d8611790a90b192551fc326eb12be22c5ca700eb91be1d60e366f9f665cb