You're on your way to the next level! Join the Kudos program to earn points and save your progress.
Level 1: Seed
25 / 150 points
Next: Root
1 badge earned
Challenges come and go, but your rewards stay with you. Do more to earn more!
What goes around comes around! Share the love by gifting kudos to your peers.
Keep earning points to reach the top of the leaderboard. It resets every quarter so you always have a chance!
Join now to unlock these features and more
The Atlassian Community can help you and your team get more value out of Atlassian products and practices.
Is anyone else using Tenable to scan their servers for security vulnerabilities like CVE-2021-44228?
It appears that Tenable does not recognize the remediation for Bitbucket / Elasticsearch.
-Dlog4j2.formatMsgNoLookups=true
From what I can tell Atlassian cannot create a new bundled version of Bitbucket / Elasticsearch because of licensing agreements.
From Atlassian: We are unable to release an updated version of the bundled Elasticsearch version due to licensing changes for Elasticsearch versions later than 7.10
This means the file that Tenable is finding in the scan for an old version of the log4j jar file is going to remain on the server and continue to report as a vulnerability.
This also means the most current version of Elasticsearch that will work with Bitbucket is version 7.10.
I am curious if anyone else is in this situation with Tenable scans and what they might be doing to address this.
Thanks, Chris
Hi Chris - Same issue here. Tenable is flagging even with the new updates and security isn't liking the response from bitbucket on not updating the bundled version. Have you come to any solutions on your end?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.