Lucene search

K
atlassianBturnerATLASSIAN:BSERV-13093
HistoryDec 17, 2021 - 7:03 p.m.

Upgrade Logback for CVE-2021-42550

2021-12-1719:03:40
bturner
jira.atlassian.com
31

0.016 Low

EPSS

Percentile

87.3%

h3. Issue Summary

In the wake of Log4Shell, CVE-2021-42550 has been created for similar JNDI considerations in Logback. The Logback maintainers have removed some functionality from Logback in response and released Logback 1.2.9.

Please note: There is no RCE in Logback, and there is no vulnerability in Bitbucket Server or Logback’s default configurations. There is also no mechanism whereby a malicious client can attack the system. Exercising CVE-2021-42550 requires write access to Bitbucket Server’s Logback configuration.

h3. Workaround

Manually audit logging configuration and ensure proper permissions.