There was a recent vulnerability of Spring break with spring data rest components and spring boot.
https://www.theregister.co.uk/2018/03/05/rest_vuln/
I am using JIRA 7.7.0, Confluence 6.4.1, Bitbucket 5.4.1.
Are these versions vulnerable to the specified bug. If so, which are the updated versions that have the patch for this issue.
PS: I was able to check the spring boot version as v1.5.6 for Bitbucket, from logs while restarting the application.
Please always read official information from the vendor not published articles that are mostly confusing and written to start global panic and increase views of page or article.
https://spring.io/blog/2018/03/06/security-issue-in-spring-data-rest-cve-2017-8046
In the JIRA/Confluence I do not see any specific libraries in the pom.xml of the source code, so probably not using them to build Atlassian products. Anyway if there is any risk I think that Atlassian team will definitely check that closely.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.