Showing results for 
Search instead for 
Did you mean: 
Sign up Log in
It's not the same without you

Join the community to find out what other Atlassian users are discussing, debating and creating.

Atlassian Community Hero Image Collage

Tenable Scans - log4j - Bitbucket/Elasticsearch

Is anyone else using Tenable to scan their servers for security vulnerabilities like CVE-2021-44228?

It appears that Tenable does not recognize the remediation for Bitbucket / Elasticsearch.


From what I can tell Atlassian cannot create a new bundled version of Bitbucket / Elasticsearch because of licensing agreements.

From Atlassian: We are unable to release an updated version of the bundled Elasticsearch version due to licensing changes for Elasticsearch versions later than 7.10

This means the file that Tenable is finding in the scan for an old version of the log4j jar file is going to remain on the server and continue to report as a vulnerability.

This also means the most current version of Elasticsearch that will work with Bitbucket is version 7.10.

I am curious if anyone else is in this situation with Tenable scans and what they might be doing to address this.

Thanks, Chris

1 answer

Hi Chris - Same issue here.  Tenable is flagging even with the new updates and security isn't liking the response from bitbucket on not updating the bundled version.  Have you come to any solutions on your end?

Hi John,

So far, we have not come up with a solution.   

Suggest an answer

Log in or Sign up to answer
Community showcase
Published in Bitbucket

📣 Calling Bitbucket Data Center customers to participate in research

Hi everyone, Are you Bitbucket DC customer? If so, we'd love to talk to you! Our team wants to dive deep to understand your long-term plans regarding Bitbucket DC and Atlassian Cloud. Do you plan...

224 views 2 5
Read article

Community Events

Connect with like-minded Atlassian users at free events near you!

Find an event

Connect with like-minded Atlassian users at free events near you!

Unfortunately there are no Community Events near you at the moment.

Host an event

You're one step closer to meeting fellow Atlassian users at your local event. Learn more about Community Events

Events near you