News: 1661796494

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Critical hole in Atlassian Bitbucket allows any miscreant to hijack servers

(2022/08/29)


A critical command-injection vulnerability in multiple API endpoints of Atlassian Bitbucket Server and Data Center could allow an unauthorized attacker to remotely execute malware, and view, change, and even delete data stored in repositories.

Atlassian has [1]fixed the security holes, which are present in versions 7.0.0 to 8.3.0 of the software, inclusive. Luckily there are no known exploits in the wild.

But considering the vulnerability, tracked as [2]CVE-2022-36804 , received a 9.9 out of 10 CVSS score in terms of severity, we'd suggest you stop what you're doing and update as soon as possible as it's safe to assume miscreants are already scanning for vulnerable instances.

[3]

As Atlassian explains in its security advisory, published mid-last week: "An attacker with access to a public repository or with read permissions to a private Bitbucket repository can execute arbitrary code by sending a malicious HTTP request."

[4]

[5]

Additionally, the Center for Internet Security has [6]labeled the flaw a "high" security risk for all sizes of business and government entities. These outfits typically use Bitbucket for managing source code in Git repositories.

Atlassian recommends organizations upgrade their instances to a fixed version, and those with configured Bitbucket Mesh nodes will need to update those, too. There's a [7]compatibility matrix to help users find the Mesh version that's compatible with the Bitbucket Data Center version.

[8]

And if you need to postpone a Bitbucket update, Atlassian advises [9]turning off public repositories globally as a temporary mitigation. This will change the attack vector from an unauthorized to an authorized attack. However, "this can not be considered a complete mitigation as an attacker with a user account could still succeed," according to the advisory.

Security researcher [10]@TheGrandPew discovered and reported the vulnerability via Atlassian's bug bounty program.

[11]If you haven't patched Zimbra holes by now, assume you're toast

[12]Warning over Java libraries and deserialization security weaknesses

[13]Atlassian reveals critical flaws in almost everything it makes and touches

[14]Atlassian boasts strong Q3 revenue growth in wake of two-week outage

This latest bug follows a series of hits for the popular enterprise collaboration software maker.

Last month, Atlassian [15]warned users of its Bamboo, Bitbucket, Confluence, Fisheye, Crucible, and Jira products that a pair of years-old, critical flaws threaten their security. It detailed the so-called Servlet Filter dispatcher vulnerabilities in its [16]July security updates , and said the flaw allowed remote, unauthenticated attackers to bypass authentication used by third-party apps.

In June, Atlassian [17]copped to another critical flaw in Confluence that was under active attack.

[18]

Plus, there was also the two-week-long [19]embarrassing cloud outage that affected almost 800 customers this spring. This is less than half a percent of the company's total customers, but still, as co-founder and co-CEO Mike Cannon-Brookes [20]admitted on the firm's most recent earnings call, it's "one customer is too many." And definitely not a good look for a cloud collaboration business. ®

Get our [21]Tech Resources



[1] https://jira.atlassian.com/browse/BSERV-13438

[2] https://www.cve.org/CVERecord?id=CVE-2022-36804

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yw02-ed0nRpOJYWTVgS0ZQAAAE0&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yw02-ed0nRpOJYWTVgS0ZQAAAE0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yw02-ed0nRpOJYWTVgS0ZQAAAE0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.cisecurity.org/advisory/a-vulnerability-in-atlassian-bitbucket-server-and-data-center-could-allow-for-remote-code-execution_2022-0107

[7] https://confluence.atlassian.com/bitbucketserver/bitbucket-mesh-compatibility-matrix-1127254859.html

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yw02-ed0nRpOJYWTVgS0ZQAAAE0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://confluence.atlassian.com/bitbucketserver/allowing-public-access-to-code-776639799.html#Allowingpublicaccesstocode-Disablingpublicaccessglobally

[10] https://twitter.com/TheGrandPew

[11] https://www.theregister.com/2022/08/23/cisa_zimbra_signatures/

[12] https://www.theregister.com/2022/08/22/java_library_flaws/

[13] https://www.theregister.com/2022/07/21/atlassian_critical_security_advisories/

[14] https://www.theregister.com/2022/04/29/atlassian_q3_2022/

[15] https://www.theregister.com/2022/07/21/atlassian_critical_security_advisories/

[16] https://confluence.atlassian.com/security/july-2022-atlassian-security-advisories-overview-1142446703.html

[17] https://www.theregister.com/2022/06/03/atlassian_confluence_critical_flaw_attacked/

[18] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yw02-ed0nRpOJYWTVgS0ZQAAAE0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[19] https://www.theregister.com/2022/04/11/atlassian_outage_backups/

[20] https://www.theregister.com/2022/04/29/atlassian_q3_2022/

[21] https://whitepapers.theregister.com/



petef

It's a good thing then that I migrated my repos away from Bitbucket when they sunsetted Mercurial.

My band career ended late in my senior year when John Cooper and I threw my
amplifier out the dormitory window. We did not act in haste. First we
checked to make sure the amplifier would fit through the frame, using the
belt from my bathrobe to measure, then we picked up the amplifier and backed
up to my bedroom door. Then we rushed forward, shouting "The WHO! The
WHO!" and we launched my amplifier perfectly, as though we had been doing it
all our lives, clean through the window and down onto the sidewalk, where a
small but appreciative crowd had gathered. I would like to be able to say
that this was a symbolic act, an effort on my part to break cleanly away
from one state in my life and move on to another, but the truth is, Cooper
and I really just wanted to find out what it would sound like. It sounded
OK.
-- Dave Barry, "The Snake"