Atlassian announced three separate security advisories for Bitbucket Server and Data Center products on 15 January, 2020. This article is designed to help you determine which advisory may apply to you and how to ask for help here on Community.
Note: Bitbucket Cloud is not affected. Customers who have upgraded Bitbucket Server to versions 5.16.11, 6.0.11, 6.1.9, 6.2.7, 6.3.6, 6.4.4, 6.5.3, 6.6.3, 6.7.3, 6.8.2, 6.9.1 or higher are not affected.
Affected Versions
Fixed Versions
We recommend upgrading your Bitbucket Server and Data Center instances to one of the following versions:
CVE-2019-15010
Affects Bitbucket Server and Data Center versions starting from 3.0.
Please read the advisory for full details.
If you have questions specifically about CVE-2019-15010, please use this link to ask here on Community.
CVE-2019-20097
Affects Bitbucket Server and Data Center versions starting from 1.0.
Please read the advisory for full details.
If you have questions specifically about CVE-2019-15010, please use this link to ask here on Community.
CVE-2019-15012
Affects Bitbucket Server and Data Center versions >= 4.13.
Please read the advisory for full details.
If you have questions specifically about CVE-2019-15010, please use this link to ask here on Community.
Mitigations
If you are not able to upgrade Bitbucket server immediately, as a temporary workaround, you can use the following steps:
For CVE-2019-15012, the edit-file feature can be disabled by following the steps below:
In bitbucket.properties, set feature.file.editor=false
See Bitbucket Server config properties for more details.
There are no known workarounds for CVE-2019-15010 or CVE-2019-20097, so it's important to upgrade to a fixed version as soon as possible.
Shannon S
Confluence Cloud Support Engineer
Atlassian
Amsterdam, Netherlands
1,001 accepted answers
0 comments