BitBucket²ÎÊý×¢Èë·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-09-23

¡ñ·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-15000£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º9.8


¡ñÓ°Ïì°æ±¾


version < 5.16.10

6.0.0 <= version < 6.0.10

6.1.0 <= version < 6.1.8

6.2.0 <= version < 6.2.6

6.3.0 <= version < 6.3.5

6.4.0 <= version < 6.4.3

6.5.0 <= version < 6.5.2


¡ñ·ì϶¸ÅÊö


Atlassian Bitbucket ServerºÍAtlassian Bitbucket Data Center¶¼ÊǰĴóÀûÑÇAtlassian¹«Ë¾µÄ²úÆ· ¡£Atlassian Bitbucket ServerÊÇÒ»¿îGit´úÂëÍйܽâ¾ö¹æ»® ¡£¸Ã¹æ»®¿ÉÄÜÖÎÀí²¢Éó²é´úÂ룬ӵÓвî¾àÊÓͼ¡¢JIRA¼¯³ÉºÍ¹¹½¨¼¯³ÉµÈÖ°ÄÜ ¡£Atlassian Bitbucket Data CenterÊÇAtlassian BitbucketµÄÊý¾ÝÖÐÐİ汾 ¡£


½üÈÕ£¬Atlassian ¹Ù·½°ä²¼Á˹ØÓÚAtlassian Bitbucke·ì϶²¼¸æ£¬Atlassian Bitbucket ServerºÍAtlassian Bitbucket Data CenterÖдæÔÚ×¢Èë·ì϶£¬ÔÊÐí¹¥»÷ÕßÏòGitºÅÁî×¢Èë¶î±íµÄ²ÎÊý£¬Õâ¿ÉÄܵ¼ÖÂÔ¶³ÌºÅÁîÖ´ÐÐ ¡£ÈôÊÇÔ¶³Ì¹¥»÷Õß¿ÉÄܽӼûBitbucket Server»òBitbucket Data CenterÖеÄGit´æ´¢¿â£¬ÔòÄܹ»ÀûÓô˲ÎÊý×¢Èë·ì϶ ¡£ÈôÊÇΪÏîÄ¿»ò´æ´¢¿âÆôÓÃÁ˹«¹²½Ó¼û£¬Ôò¹¥»÷ÕßÄܹ»ÄäÃûÀûÓô˷ì϶ ¡£


¡ñ·ì϶ÑéÖ¤


ÔÝÎÞPOC¡¢EXP ¡£


¡ñ½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬²¹¶¡»ñÈ¡Á´½Ó£º

https://jira.atlassian.com/browse/BSERV-11947


¡ñ²Î¿¼Á´½Ó


https://jira.atlassian.com/browse/BSERV-11947

https://confluence.atlassian.com/bitbucketserver/bitbucket-server-security-advisory-2019-09-18-976762635.html