Are JIRA, Confluence & Bitbucket impacted by the Spring break vulnerability

Abhilash_Marampelli March 8, 2018

There was a recent vulnerability of Spring break with spring data rest components and spring boot.

https://www.theregister.co.uk/2018/03/05/rest_vuln/

I am using JIRA 7.7.0, Confluence 6.4.1, Bitbucket 5.4.1.

Are these versions vulnerable to the specified bug. If so, which are the updated versions that have the patch for this issue.

PS: I was able to check the spring boot version as v1.5.6 for Bitbucket, from logs while restarting the application. 

1 answer

1 vote
Mirek
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
March 9, 2018

Please always read official information from the vendor not published articles that are mostly confusing and written to start global panic and increase views of page or article.

https://spring.io/blog/2018/03/06/security-issue-in-spring-data-rest-cve-2017-8046

In the JIRA/Confluence I do not see any specific libraries in the pom.xml of the source code, so probably not using them to build Atlassian products. Anyway if there is any risk I think that Atlassian team will definitely check that closely.

Abhilash_Marampelli March 11, 2018

Thanks for the detail @Mirek. Appreciate your inputs. 

Suggest an answer

Log in or Sign up to answer