Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

Bitbucket server and CVE-2017-12615

ChrisB September 21, 2017

Please comment on whether or not Bitbucket Server on Windows is affected by CVE-2017-12615 and which versions are and are not affected.

3 answers

1 accepted

2 votes
Answer accepted
Julius Davies _bit-booster_com_
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
September 21, 2017

This is not an official answer (I'm not Atlassian staff), but based on a quick glance at the CVE report and what versions of Tomcat are included in Bitbucket, I think this only affects Stash 3.11.6 or older.

CVE-2017-12615 appears to only affect systems using Tomcat 7.x.

Bitbucket 4.0 or newer uses Tomcat 8.x according to the End of support announcements for Bitbucket Server page.

1 vote
Felipe Kraemer
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
September 21, 2017

Hello @ChrisB,

@Julius Davies _bit-booster_com_ is right. As mentioned to you in the support ticket you have created, the security team has reviewed the vulnerability and has determined that the vulnerability CVE-2017-12615 affects Tomcat 7.0.0 to 7.0.79, and was fixed in revisions 1804604 and 1804729.

According to the announcement from 10 September 2014 at the End of support announcements for Bitbucket Server page, Atlassian would be including Tomcat 8 libraries from Bitbucket Server 4.0 onwards, so all Bitbucket Server versions before 4.0 are likely affected by this vulnerability and all versions from 4.0 onwards are not.

 

 

Please let me know if you need any further clarifications.

Cheers,
Felipe Kraemer

1 vote
Nic Brough -Adaptavist-
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
September 21, 2017

Probably better asked of Atlassian for an answer than the Community.  Https://support.atlassian.com/contact will get you an official answer (we'd ask you to share it here, for info)

ChrisB September 21, 2017

Good suggestion. I will report back

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events