Bitbucket and Confluence DC critical vulnerability

By in
Bitbucket and Confluence DC critical vulnerability

Bitbucket Data Center and Confluence Data Center are vulnerable to Java deserialization attacks (CVE-2016-10750). It`s because of Hazelcast, third-party software, which Attlassian DC appliations use for running as a cluster. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted JoinRequest, resulting in arbitrary code execution. You should upgrade your instances to the safe version or use a provided workaround as soon as possible. More info HERE.

Leave a reply

Your email address will not be published.