Lucene search

K
atlassianMsucheckiBSERV-14091
HistoryMay 17, 2023 - 6:46 a.m.

Upgrade spring-core for CVE-2023-20860

2023-05-1706:46:56
msuchecki
jira.atlassian.com
67
bitbucket server
vulnerability
update
library
scanner
workaround

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

0.001 Low

EPSS

Percentile

36.7%

h3. Issue Summary

Bitbucket Server/DC includes the following two libraries, which may be vulnerable to [CVE-2023-20860|https://vulners.com/cve/CVE-2023-20860]:

  • <INSTALL_PATH>/app/WEB-INF/lib/spring-core-5.3.23.jar
  • <INSTALL_PATH>/opensearch/plugins/opensearch-sql/spring-core-5.3.22.jar

Bitbucket isn’t known to be vulnerable, but the vulnerability may still be reported by scanners, so it is necessary to update the library since Bitbucket uses a version that’s reported to be vulnerable.
h3. Workaround

Currently there is no known workaround for this behavior. A workaround will be added here when available

Affected configurations

Vulners
Node
atlassianbitbucket_data_centerRange7.17.0
OR
atlassianbitbucket_data_centerRange7.21.0
OR
atlassianbitbucket_data_centerRange8.9.0
OR
atlassianbitbucket_data_centerRange<7.17.16
OR
atlassianbitbucket_data_centerRange<7.21.11
OR
atlassianbitbucket_data_centerRange<8.5.4
OR
atlassianbitbucket_data_centerRange<8.6.4
OR
atlassianbitbucket_data_centerRange<8.7.3
OR
atlassianbitbucket_data_centerRange<8.9.1
OR
atlassianbitbucket_data_centerRange<8.10.0

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

0.001 Low

EPSS

Percentile

36.7%