Hello,
out security team reported, that the integrated SSH server in Bitbucket is vulnerable to a weakness called terrapin, which allows man-in-the-middle-attack.
What is the status regarding a security update? Bitbucket 7.21.22 was released but if we belive the changelog, there is no terrapin fix inside.
This is worrying.
We really need a guide or better information on this.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.