BitBucket²ÎÊý×¢ÈëÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-09-23¡ñÎó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-15000£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬CVSS·ÖÖµ£º9.8
¡ñÓ°Ïì°æ±¾
version < 5.16.10
6.0.0 <= version < 6.0.10
6.1.0 <= version < 6.1.8
6.2.0 <= version < 6.2.6
6.3.0 <= version < 6.3.5
6.4.0 <= version < 6.4.3
6.5.0 <= version < 6.5.2
¡ñÎó²î¸ÅÊö
Atlassian Bitbucket ServerºÍAtlassian Bitbucket Data Center¶¼ÊǰĴóÀûÑÇAtlassian¹«Ë¾µÄ²úÆ·¡£¡£¡£Atlassian Bitbucket ServerÊÇÒ»¿îGit´úÂëÍйܽâ¾ö¼Æ»®¡£¡£¡£¸Ã¼Æ»®Äܹ»ÖÎÀí²¢Éó²é´úÂ룬£¬£¬¾ßÓвî±ðÊÓͼ¡¢JIRA¼¯³ÉºÍ¹¹½¨¼¯³ÉµÈ¹¦Ð§¡£¡£¡£Atlassian Bitbucket Data CenterÊÇAtlassian BitbucketµÄÊý¾ÝÖÐÐİ汾¡£¡£¡£
¿ËÈÕ£¬£¬£¬Atlassian ¹Ù·½Ðû²¼Á˹ØÓÚAtlassian BitbuckeÎó²îͨ¸æ£¬£¬£¬Atlassian Bitbucket ServerºÍAtlassian Bitbucket Data CenterÖб£´æ×¢ÈëÎó²î£¬£¬£¬ÔÊÐí¹¥»÷ÕßÏòGitÏÂÁî×¢ÈëÌØÁíÍâ²ÎÊý£¬£¬£¬Õâ¿ÉÄܵ¼ÖÂÔ¶³ÌÏÂÁîÖ´ÐС£¡£¡£ÈôÊÇÔ¶³Ì¹¥»÷ÕßÄܹ»»á¼ûBitbucket Server»òBitbucket Data CenterÖеÄGit´æ´¢¿â£¬£¬£¬Ôò¿ÉÒÔʹÓô˲ÎÊý×¢ÈëÎó²î¡£¡£¡£ÈôÊÇΪÏîÄ¿»ò´æ´¢¿âÆôÓÃÁ˹«¹²»á¼û£¬£¬£¬Ôò¹¥»÷Õß¿ÉÒÔÄäÃûʹÓôËÎó²î¡£¡£¡£
¡ñÎó²îÑéÖ¤
ÔÝÎÞPOC¡¢EXP¡£¡£¡£
¡ñÐÞ¸´½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£º
https://jira.atlassian.com/browse/BSERV-11947
¡ñ²Î¿¼Á´½Ó
https://jira.atlassian.com/browse/BSERV-11947
https://confluence.atlassian.com/bitbucketserver/bitbucket-server-security-advisory-2019-09-18-976762635.html


¾©¹«Íø°²±¸11010802024551ºÅ