Hi,
Regarding latest Bitbucket Server security advisory, would you suggest us to upgrade if we have 4.12 ?
Thank you
Just to confirm, Samuel, Bitbucket Server 4.12 is not affected by CVE-2018-5225. CVE-2018-5225 only affects versions 4.13+ (until the fixed versions), which is where we introduced the file editing feature which this vulnerability is related to. Since your version, 4.12, does not have this feature, it is not affected. More information about fixed versions can be found on https://confluence.atlassian.com/bitbucketserver/bitbucket-server-security-advisory-2018-03-21-946627549.html
In general upgrading Bitbucket Server will provide you with new features, bug fixes, and performance improvements. So it's a good idea to keep updated, but you don't need to upgrade as a direct result of this security vulnerability. More information on upgrading can be found at https://confluence.atlassian.com/bitbucketserver/bitbucket-server-upgrade-guide-776640551.html
If you see your version of Bitbucket affected here (https://confluence.atlassian.com/bitbucketserver/bitbucket-server-security-advisories-776640597.html), you should upgrade.
I've seen attempted hacks on instances that were listed on Atlassian's Security Advisories before.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.