Missed Team ’24? Catch up on announcements here.

×
Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

Multiple Products Security Advisory - CVE-2022-26136, CVE-2022-26137

Rashmi July 21, 2022

Hi Team!

For bitbucket datacenter we are running on version v7.8.0, in the version list atlassian has provided it says 

  • All versions 7.7.x through 7.16.x

But in fixed version they have provided , it says -

Bitbucket Server and Data Center

  • 7.6.x >= 7.6.16 (LTS)

  • 7.17.x >= 7.17.8 (LTS)

  • 7.19.x >= 7.19.5

  • 7.20.x >= 7.20.2

  • 7.21.x >= 7.21.2 (LTS)

  • 8.0.x >= 8.0.1

  • 8.1.x >= 8.1.1

  • Versions >= 8.2.0

We need a clarity on this, if version 7.8.0 is impacted and if yes which is fixed version for this?

You help is much appreciated!

 

Regards,

Rashmi

1 answer

0 votes
Christian Glockner
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
July 21, 2022

Hi Rashmi,

Yes, as stated

  • All versions 7.7.x through 7.16.x

are affected, so that includes 7.8.0.

The next highest version you can upgrade to that contains the fix is 7.17.8.

Cheers,

Christian
Premier Support Engineer

Atlassian

Alin Faur July 22, 2022

Is there any chance for identifying a workaround that would only patch applications in their existing version instead of having to upgrade?

Christian Glockner
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
July 22, 2022

Hi Alin,

Upgrading is the only way to resolve this vulnerability.

Cheers,

Christian

Premier Support Engineer

Atlassian

Like Alin Faur likes this

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
SERVER
TAGS
AUG Leaders

Atlassian Community Events