Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Bitbucket Server security advisory do you suggest us to upgrade if we have 4.12 ?

Samuel Levesque
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
April 3, 2018

Hi, 

Regarding latest Bitbucket Server security advisory, would you suggest us to upgrade if we have 4.12 ?

 

Thank you

2 answers

1 accepted

2 votes
Answer accepted
Jeff Thomas
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
April 3, 2018

Just to confirm, Samuel, Bitbucket Server 4.12 is not affected by CVE-2018-5225. CVE-2018-5225 only affects versions 4.13+ (until the fixed versions), which is where we introduced the file editing feature which this vulnerability is related to. Since your version, 4.12, does not have this feature, it is not affected. More information about fixed versions can be found on https://confluence.atlassian.com/bitbucketserver/bitbucket-server-security-advisory-2018-03-21-946627549.html

In general upgrading Bitbucket Server will provide you with new features, bug fixes, and performance improvements. So it's a good idea to keep updated, but you don't need to upgrade as a direct result of this security vulnerability. More information on upgrading can be found at https://confluence.atlassian.com/bitbucketserver/bitbucket-server-upgrade-guide-776640551.html

0 votes
Timothy
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
April 3, 2018

If you see your version of Bitbucket affected here (https://confluence.atlassian.com/bitbucketserver/bitbucket-server-security-advisories-776640597.html), you should upgrade.

I've seen attempted hacks on instances that were listed on Atlassian's Security Advisories before.

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events