There was a recent vulnerability of Spring break with spring data rest components and spring boot.
https://www.theregister.co.uk/2018/03/05/rest_vuln/
I am using JIRA 7.7.0, Confluence 6.4.1, Bitbucket 5.4.1.
Are these versions vulnerable to the specified bug. If so, which are the updated versions that have the patch for this issue.
PS: I was able to check the spring boot version as v1.5.6 for Bitbucket, from logs while restarting the application.
Please always read official information from the vendor not published articles that are mostly confusing and written to start global panic and increase views of page or article.
https://spring.io/blog/2018/03/06/security-issue-in-spring-data-rest-cve-2017-8046
In the JIRA/Confluence I do not see any specific libraries in the pom.xml of the source code, so probably not using them to build Atlassian products. Anyway if there is any risk I think that Atlassian team will definitely check that closely.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.