Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in
Celebration

Earn badges and make progress

You're on your way to the next level! Join the Kudos program to earn points and save your progress.

Deleted user Avatar
Deleted user

Level 1: Seed

25 / 150 points

Next: Root

Avatar

1 badge earned

Collect

Participate in fun challenges

Challenges come and go, but your rewards stay with you. Do more to earn more!

Challenges
Coins

Gift kudos to your peers

What goes around comes around! Share the love by gifting kudos to your peers.

Recognition
Ribbon

Rise up in the ranks

Keep earning points to reach the top of the leaderboard. It resets every quarter so you always have a chance!

Leaderboard

Come for the products,
stay for the community

The Atlassian Community can help you and your team get more value out of Atlassian products and practices.

Atlassian Community about banner
4,462,878
Community Members
 
Community Events
176
Community Groups

Tenable Scans - log4j - Bitbucket/Elasticsearch

Is anyone else using Tenable to scan their servers for security vulnerabilities like CVE-2021-44228?

It appears that Tenable does not recognize the remediation for Bitbucket / Elasticsearch.

    -Dlog4j2.formatMsgNoLookups=true

From what I can tell Atlassian cannot create a new bundled version of Bitbucket / Elasticsearch because of licensing agreements.

From Atlassian: We are unable to release an updated version of the bundled Elasticsearch version due to licensing changes for Elasticsearch versions later than 7.10

This means the file that Tenable is finding in the scan for an old version of the log4j jar file is going to remain on the server and continue to report as a vulnerability.

This also means the most current version of Elasticsearch that will work with Bitbucket is version 7.10.


I am curious if anyone else is in this situation with Tenable scans and what they might be doing to address this.


Thanks, Chris

1 answer

Hi Chris - Same issue here.  Tenable is flagging even with the new updates and security isn't liking the response from bitbucket on not updating the bundled version.  Have you come to any solutions on your end?

Hi John,

So far, we have not come up with a solution.   

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
SERVER
TAGS

Atlassian Community Events