Atlassian announced three separate security advisories for Bitbucket Server and Data Center products on 15 January, 2020. This article is designed to help you determine which advisory may apply to you and how to ask for help here on Community.
Note: Bitbucket Cloud is not affected. Customers who have upgraded Bitbucket Server to versions 5.16.11, 6.0.11, 6.1.9, 6.2.7, 6.3.6, 6.4.4, 6.5.3, 6.6.3, 6.7.3, 6.8.2, 6.9.1 or higher are not affected.
Affected Versions
Fixed Versions
We recommend upgrading your Bitbucket Server and Data Center instances to one of the following versions:
CVE-2019-15010
Affects Bitbucket Server and Data Center versions starting from 3.0.
Please read the advisory for full details.
If you have questions specifically about CVE-2019-15010, please use this link to ask here on Community.
CVE-2019-20097
Affects Bitbucket Server and Data Center versions starting from 1.0.
Please read the advisory for full details.
If you have questions specifically about CVE-2019-15010, please use this link to ask here on Community.
CVE-2019-15012
Affects Bitbucket Server and Data Center versions >= 4.13.
Please read the advisory for full details.
If you have questions specifically about CVE-2019-15010, please use this link to ask here on Community.
Mitigations
If you are not able to upgrade Bitbucket server immediately, as a temporary workaround, you can use the following steps:
For CVE-2019-15012, the edit-file feature can be disabled by following the steps below:
In bitbucket.properties, set feature.file.editor=false
See Bitbucket Server config properties for more details.
There are no known workarounds for CVE-2019-15010 or CVE-2019-20097, so it's important to upgrade to a fixed version as soon as possible.
Shannon S
Confluence Cloud Support Engineer
Atlassian
Amsterdam, Netherlands
1,006 accepted answers
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
0 comments