Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Are JIRA, Confluence & Bitbucket impacted by the Spring break vulnerability

Abhilash_Marampelli March 8, 2018

There was a recent vulnerability of Spring break with spring data rest components and spring boot.

https://www.theregister.co.uk/2018/03/05/rest_vuln/

I am using JIRA 7.7.0, Confluence 6.4.1, Bitbucket 5.4.1.

Are these versions vulnerable to the specified bug. If so, which are the updated versions that have the patch for this issue.

PS: I was able to check the spring boot version as v1.5.6 for Bitbucket, from logs while restarting the application. 

1 answer

1 vote
Mirek
Community Champion
March 9, 2018

Please always read official information from the vendor not published articles that are mostly confusing and written to start global panic and increase views of page or article.

https://spring.io/blog/2018/03/06/security-issue-in-spring-data-rest-cve-2017-8046

In the JIRA/Confluence I do not see any specific libraries in the pom.xml of the source code, so probably not using them to build Atlassian products. Anyway if there is any risk I think that Atlassian team will definitely check that closely.

Abhilash_Marampelli March 11, 2018

Thanks for the detail @Mirek. Appreciate your inputs. 

Suggest an answer

Log in or Sign up to answer