Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

Is version 7.5.1 vulnerable to log4j exploit?

Robert Eanes December 15, 2021

Is version 7.5.1 vulnerable to log4j exploit?

2 answers

1 vote
Daniel Eads
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
December 15, 2021

Hi all,

Daniel from Atlassian Support - I'd like to let you know that we have updated the advisory to include more information about Bitbucket Server, Bitbucket Data Center, and the bundled elasticsearch product. Please refer to the advisory for the most current guidance:

Thanks,
Daniel Eads | Atlassian Support 

0 votes
Fabio Racobaldo _Herzum_
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
December 15, 2021

Hi @Robert Eanes ,

B

itbucket is NOT affected.

https://confluence.atlassian.com/kb/faq-for-cve-2021-44228-1103069406.html

I see Bitbucket Server/Data Center isn't in the list of products using Log4j but I can see Log4j JAR files in my installation directory, is my instance vulnerable?

No. Neither Bitbucket Server nor Data Center use Log4j, they use Logback.

 

Hope this helps,

Fabio

Craig Castle-Mead
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
December 15, 2021

Bitbucket allows you to run an external Elasticsearch environment instead of the bundled version, so ensure you check the Elasticsearch config/version/exposure as well as the main product.

CCM

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events