BitBucket²ÎÊý×¢ÈëÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-09-23

¡ñÎó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-15000£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬CVSS·ÖÖµ£º9.8


¡ñÓ°Ïì°æ±¾


version < 5.16.10

6.0.0 <= version < 6.0.10

6.1.0 <= version < 6.1.8

6.2.0 <= version < 6.2.6

6.3.0 <= version < 6.3.5

6.4.0 <= version < 6.4.3

6.5.0 <= version < 6.5.2


¡ñÎó²î¸ÅÊö


Atlassian Bitbucket ServerºÍAtlassian Bitbucket Data Center¶¼ÊǰĴóÀûÑÇAtlassian¹«Ë¾µÄ²úÆ·¡£¡£¡£Atlassian Bitbucket ServerÊÇÒ»¿îGit´úÂëÍйܽâ¾ö¼Æ»®¡£¡£¡£¸Ã¼Æ»®Äܹ»ÖÎÀí²¢Éó²é´úÂ룬£¬£¬¾ßÓвî±ðÊÓͼ¡¢JIRA¼¯³ÉºÍ¹¹½¨¼¯³ÉµÈ¹¦Ð§¡£¡£¡£Atlassian Bitbucket Data CenterÊÇAtlassian BitbucketµÄÊý¾ÝÖÐÐİ汾¡£¡£¡£


¿ËÈÕ£¬£¬£¬Atlassian ¹Ù·½Ðû²¼Á˹ØÓÚAtlassian BitbuckeÎó²îͨ¸æ£¬£¬£¬Atlassian Bitbucket ServerºÍAtlassian Bitbucket Data CenterÖб£´æ×¢ÈëÎó²î£¬£¬£¬ÔÊÐí¹¥»÷ÕßÏòGitÏÂÁî×¢ÈëÌØÁíÍâ²ÎÊý£¬£¬£¬Õâ¿ÉÄܵ¼ÖÂÔ¶³ÌÏÂÁîÖ´ÐС£¡£¡£ÈôÊÇÔ¶³Ì¹¥»÷ÕßÄܹ»»á¼ûBitbucket Server»òBitbucket Data CenterÖеÄGit´æ´¢¿â£¬£¬£¬Ôò¿ÉÒÔʹÓô˲ÎÊý×¢ÈëÎó²î¡£¡£¡£ÈôÊÇΪÏîÄ¿»ò´æ´¢¿âÆôÓÃÁ˹«¹²»á¼û£¬£¬£¬Ôò¹¥»÷Õß¿ÉÒÔÄäÃûʹÓôËÎó²î¡£¡£¡£


¡ñÎó²îÑéÖ¤


ÔÝÎÞPOC¡¢EXP¡£¡£¡£


¡ñÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£º

https://jira.atlassian.com/browse/BSERV-11947


¡ñ²Î¿¼Á´½Ó


https://jira.atlassian.com/browse/BSERV-11947

https://confluence.atlassian.com/bitbucketserver/bitbucket-server-security-advisory-2019-09-18-976762635.html