Is this vulnerability affecting the Bitbucket versions 2.8.10, 2.8.11.2, 2.3.2, and 2.5.3?
If yes, is there patch/fix or when they would be ready?
Thanks
Hey Richard, welcome to the Community!
Bitbucket Server was not affected by CVE-2018-11307 as it does not include the iBatis library that was affected in the advisory. Thanks for playing it safe and checking!
Cheers,
Daniel | Atlassian Support
Hey Daniel, thank you very much for your prompt response. Now I can breathe easy, knowing that my Bitbucket versions are not affected by the Jackson-databind vulnerability.
Thanks again for your support,
Richard.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.