Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in
Celebration

Earn badges and make progress

You're on your way to the next level! Join the Kudos program to earn points and save your progress.

Deleted user Avatar
Deleted user

Level 1: Seed

25 / 150 points

Next: Root

Avatar

1 badge earned

Collect

Participate in fun challenges

Challenges come and go, but your rewards stay with you. Do more to earn more!

Challenges
Coins

Gift kudos to your peers

What goes around comes around! Share the love by gifting kudos to your peers.

Recognition
Ribbon

Rise up in the ranks

Keep earning points to reach the top of the leaderboard. It resets every quarter so you always have a chance!

Leaderboard

Come for the products,
stay for the community

The Atlassian Community can help you and your team get more value out of Atlassian products and practices.

Atlassian Community about banner
4,414,273
Community Members
 
Community Events
170
Community Groups

Bitbucket server and Datacenter security advisory 2019-09-18 - CVE-2019-15000

Every now and then a vulnerability is discovered in the tools we most often use and this is no exception for Atlassian applications. Recently a vulnerability was discovered in Bitbucket server and Datacenter where it is possible to gain control over the instance by injecting additional arguments into Git commands.

In scenarios like this, the key to success is to having a solid plan to mitigate the impact and fix it and this is all this article it's about, "I'm affected by this vulnerability, what now?!"

There are basically 3 ways to mitigate it and fix it:

  •  Disabling public access for the project or repository will prevent anonymous users to run arbitrary git commands;
  • Upgrade the instance to a version that has the fix;
  • Apply the zero downtime hotfix described in the security advisory article linked below;

Additional details about the vulnerability as well as details to apply the hotfix can be checked at the Bitbucket Server security advisory 2019-09-18 article.

2 comments

Thanks for the Article!

Like Douglas Gnoato likes this

You are most welcome Merve. Glad to help :)

Comment

Log in or Sign up to comment
TAGS

Atlassian Community Events