Every now and then a vulnerability is discovered in the tools we most often use and this is no exception for Atlassian applications. Recently a vulnerability was discovered in Bitbucket server and Datacenter where it is possible to gain control over the instance by injecting additional arguments into Git commands.
In scenarios like this, the key to success is to having a solid plan to mitigate the impact and fix it and this is all this article it's about, "I'm affected by this vulnerability, what now?!"
There are basically 3 ways to mitigate it and fix it:
Additional details about the vulnerability as well as details to apply the hotfix can be checked at the Bitbucket Server security advisory 2019-09-18 article.
Douglas Gnoato
Enterprise Support Engineer
e-Core/Atlassian
Porto Alegre, Brazil
2 comments