GNU Bash 4.3 - CVE-2014-6271 vulnerability issue - How does Altassian tools impacted?

Bash  - CVE-2014-6271 vulnerability issue - How does Altassian tools impacted? especially JIRA and Bamboo (Running on Centos 5.4 OS).

 

how that differ Cloud hosting and standalone installation?

 

Regards,

Jijo | TechNPoints

4 answers

1 accepted

0 votes
Answer accepted

Hi all

There is no vulnerability in Atlassian server products, see my blog post.

http://blogs.atlassian.com/2014/09/bash-vulnerability-atlassian/

Thanks Craig for confirmation! Good to hear from Atlassin people directly :)

I think you just need to patch up your linux to fix the vulnerability. Any software can be exposed with this bash issue. They put out a temporary patch you should update to that and when a complete fix has been done update to that.

1 vote

Atlassian systems, both OnDemand and Server versions, are not affected by this bug generally, barring two cases:

  1.  Bitbucket was vulnerable, but has been patched
  2. Where you have installed server versions on systems that are affected.  Atlassian stuff itself is not affected directly, but if they're running on an OS that is affected, then yes, they're vulnerable.  So you need to fix it at an OS level if you're using a vulnerable version of bash.

 

Thanks Nic, That make sense since Bash is part of OS component.

for the cloud issue I have not heard atlassian mention anything yet.  nothing listed in their https://confluence.atlassian.com/display/JIRA/Security+Advisories

Suggest an answer

Log in or Sign up to answer
Community showcase
Published Mar 14, 2019 in Jira

Updates to jira.atlassian.com give you visibility into what's coming in Jira Server and Data Center

Hello, Community! My name is Gosia and I'm a Product Manager on Jira Server and Data Center here at Atlassian. Since 2002 when we launched our public issue tracker, jira.atlass...

572 views 1 14
Read article

Atlassian User Groups

Connect with like-minded Atlassian users at free events near you!

Find a group

Connect with like-minded Atlassian users at free events near you!

Find my local user group

Unfortunately there are no AUG chapters near you at the moment.

Start an AUG

You're one step closer to meeting fellow Atlassian users at your local meet up. Learn more about AUGs

Groups near you