Lucene search

K
atlassianBehumphreysBSERV-13588
HistoryDec 06, 2022 - 11:56 p.m.

Upgrade OpenSearch to 1.3.7 to mitigate CVE-2022-42889

2022-12-0623:56:26
behumphreys
jira.atlassian.com
91
opensearch upgrade
mitigate cve-2022-42889
software update
release date

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.972 High

EPSS

Percentile

99.8%

In BSERV-13534 commons-text usages were upgraded in the Bitbucket Webapp to mitigate against CVE-2022-42889 (although Bitbucket WebApp was actually unaffected). The bundled OpenSearch should also be updated to 1.3.7 when it is released. The release date is currently scheduled for 13-Dec-2022: https://opensearch.org/releases.html

References:

Affected configurations

Vulners
Node
atlassianbitbucket_data_centerRange7.21.0
OR
atlassianbitbucket_data_centerRange<7.21.8
OR
atlassianbitbucket_data_centerRange<8.3.4
OR
atlassianbitbucket_data_centerRange<8.4.3
OR
atlassianbitbucket_data_centerRange<8.5.2
OR
atlassianbitbucket_data_centerRange<8.6.2
OR
atlassianbitbucket_data_centerRange<8.7.1
OR
atlassianbitbucket_data_centerRange<8.8.0

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.972 High

EPSS

Percentile

99.8%