Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

CVE-2018-11307 - FasterXML Jackson-databind (Bitbucket)

Richard Vacaflor August 2, 2019

Is this vulnerability affecting the Bitbucket versions 2.8.10, 2.8.11.2, 2.3.2, and 2.5.3?

If yes, is there patch/fix or when they would be ready?

Thanks

1 answer

1 accepted

0 votes
Answer accepted
Daniel Eads
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
August 2, 2019

Hey Richard, welcome to the Community!

Bitbucket Server was not affected by CVE-2018-11307 as it does not include the iBatis library that was affected in the advisory. Thanks for playing it safe and checking!

Cheers,
Daniel | Atlassian Support

Richard Vacaflor August 4, 2019

Hey Daniel, thank you very much for your prompt response. Now I can breathe easy, knowing that my Bitbucket versions are not affected by the Jackson-databind vulnerability.

Thanks again for your support,

Richard.

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events