It's not the same without you

Join the community to find out what other Atlassian users are discussing, debating and creating.

Atlassian Community Hero Image Collage

Bitbucket 5.5 security alert

William Castillo Oct 25, 2017

Hi I just upgraded to bitbucket 5.5 and when running service I'm receiving following alert, any advice, I don't want my files or server insecure:

 

Starting Atlassian Bitbucket as dedicated user atlbitbucket

-bash: line 20: cd: /root: Permission denied

 

Starting bundled Elasticsearch

Hint: Run start-bitbucket.sh --no-search to skip starting Elasticsearch

Bundled Elasticsearch started successfully

 

Bitbucket is being run with a umask that contains potentially unsafe settings.

The following issues were found with the mask "u=rwx,g=rwx,o=rx" (0002):

 - Access is allowed to 'others'. It is recommended that 'others' be denied

   all access for security reasons.

 - Write access is allowed to 'group'. It is recommend that 'group' be

   denied write access. Read access to a restricted group is recommended

   to allow access to the logs.

The recommended umask for Bitbucket is "u=,g=w,o=rwx" (0027) and can be

configured in _start-webapp.sh

1 answer

1 accepted

1 vote
Answer accepted
Ana Retamal Ortiz Atlassian Team Oct 26, 2017

Hi William,  does it fail to start? Or does it start despite the warning you're getting?

A similar issue was reported at Bitbucket is being run with a umask that contains potentially unsafe settings. Can you follow the advice? Most likely you just need to fix the permissions.

Let us know if you need further assistance!

Best regards,

Ana

William Castillo Oct 28, 2017

Seems it starts , I modified suggested file and alert about mask is gone, but still show alert about /root permission denied. 

Suggest an answer

Log in or Sign up to answer
This widget could not be displayed.
This widget could not be displayed.
Community showcase
Published in Bitbucket Pipelines

Building a Bitbucket Pipe as a casual coder

...ipe.sh :  #!/bin/bash source "$(dirname "$0")/common.sh" enable_debug extra_args="" if [[ "${DEBUG}" == "true" ]]; then extra_args="--verbose" fi # mandatory variables R...

1,975 views 1 19
Read article

Community Events

Connect with like-minded Atlassian users at free events near you!

Find an event

Connect with like-minded Atlassian users at free events near you!

Unfortunately there are no Community Events near you at the moment.

Host an event

You're one step closer to meeting fellow Atlassian users at your local event. Learn more about Community Events

Events near you