Hi,
Has Bitbucket (or any of the other Atlassian products required to use it) been affected by the recent "log4shell" vulnerability in Log4J?
Thanks for your help!
Hi, you can find FAQs and Atlassian recommendations and updates related to Log4J here šĀ https://confluence.atlassian.com/kb/faq-for-cve-2021-44228-1103069406.html
Hi all,
Daniel with Atlassian Support here to let you know our security team has finished its investigation. We have an official response statement here on Community, which you can access at this link.
More information can be found on our advisory page, as well as the previously-published FAQ:
Thanks,Daniel Eads | Atlassian Support
"You can check if you are vulnerable by inspecting theĀ Log4j configuration file. If you find a line containing theĀ org.apache.log4j.net.JMSAppender, you may be vulnerable. If you do not find a line containing theĀ org.apache.log4j.net.JMSAppender, you do not have this specific vulnerable configuration."
org.apache.log4j.net.JMSAppender
āļøabove is information for data-centre and server
In terms of Cloud there is a mention in FAQ that Atlassian security team is investigating the impact on Cloud but nothing specific is mentioned there yet.
ElasticSearch in our BitBucket has the affected JAR files
Ā
But Atlassian are saying Bitbucket is not affected?
Whats the deal please?
Hi, My Confluence instance used for an Opensource project has been hacked since the 22th November.
It looks like you're new here. Sign in or register to get started.