Atlassian Update
3619Warning Date
Severity Level
Warning Number
Target Sector
16 January, 2020
● Critical
2020-802
All
Description:
Atlassian has released security update to address multiple vulnerabilities in the following product:
- Bitbucket Server and Data Center
- All 1.x.x, 2.x.x, 3.x.x, 4.x.x versions
- from version 6.0.x before 6.0.11
- from version 6.1.x before 6.1.9
- from version 6.2.x before 6.2.7
- from version 6.3.x before 6.3.6
- from version 6.4.x before 6.4.4
- from version 6.5.x before 6.5.3
- from version 6.6.x before 6.6.3
- from version 6.7.x before 6.7.3
- from version 6.8.x before 6.8.2
- from version 6.9.x before 6.9.1
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Remote code execution using a specially crafted payload as user input.
- Push malicious files to a repository on the victim's system.
Best practice and Recommendations:
The CERT team encourages users to review Atlassian security advisory and apply the necessary updates: