Atlassian Bitbucket Server & Data Center


Vendor Data Vendor Patch Exists
Community Data Vulnerable

Vendor Resources

Resource Link
Multiple Products Security Advisory - Log4j Vulnerable To Remote Code Execution - CVE-2021-44228 https://confluence.atlassian.com/security/multiple-products-security-advisory-log4j-vulnerable-to-remote-code-execution-cve-2021-44228-1103069934.html

Community Resources

Resource Link
Multiple Products Security Advisory - Log4j Vulnerable To Remote Code Execution - CVE-2021-44228 https://confluence.atlassian.com/security/multiple-products-security-advisory-log4j-vulnerable-to-remote-code-execution-cve-2021-44228-1103069934.html

Community Notes

Source Note
NCSC-NL CVE-2021-4104: Not vuln ; CVE-2021-44228: Fix
NCSC-NL This product is not vulnerable to remote code execution but may leak information due to the bundled Elasticsearch component being vulnerable.
CISAGov This product is not vulnerable to remote code execution but may leak information due to the bundled Elasticsearch component being vulnerable.

Sources

Date Attribution Description
2022-01-03 11:01:35 NCSC-NL Updated vendorPatchExists. Updated community note. Updated community link Multiple Products Security Advisory - Log4j Vulnerable To Remote Code Execution - CVE-2021-44228. Updated community note.
2021-12-30 21:31:50 CISAGov Updated communityVulnerable. Updated vendorPatchExists. Updated vendor link Multiple Products Security Advisory - Log4j Vulnerable To Remote Code Execution - CVE-2021-44228. Updated community note.