Tenable Scans - log4j - Bitbucket/Elasticsearch

Christopher Montgomery December 17, 2021

Is anyone else using Tenable to scan their servers for security vulnerabilities like CVE-2021-44228?

It appears that Tenable does not recognize the remediation for Bitbucket / Elasticsearch.

    -Dlog4j2.formatMsgNoLookups=true

From what I can tell Atlassian cannot create a new bundled version of Bitbucket / Elasticsearch because of licensing agreements.

From Atlassian: We are unable to release an updated version of the bundled Elasticsearch version due to licensing changes for Elasticsearch versions later than 7.10

This means the file that Tenable is finding in the scan for an old version of the log4j jar file is going to remain on the server and continue to report as a vulnerability.

This also means the most current version of Elasticsearch that will work with Bitbucket is version 7.10.


I am curious if anyone else is in this situation with Tenable scans and what they might be doing to address this.


Thanks, Chris

1 answer

0 votes
John Reynolds December 23, 2021

Hi Chris - Same issue here.  Tenable is flagging even with the new updates and security isn't liking the response from bitbucket on not updating the bundled version.  Have you come to any solutions on your end?

Christopher Montgomery December 27, 2021

Hi John,

So far, we have not come up with a solution.   

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
SERVER
TAGS
AUG Leaders

Atlassian Community Events