QID 379560

QID 379560: Atlassian Bitbucket Data Center and Server org.xerial.snappy:snappy-java Dependency Denial of Service (DoS) Vulnerability (BSERV-19100)

Bitbucket Data Center looks like a single instance of Bitbucket Server to users, but under the hood, it consists of a cluster of multiple machines ("cluster nodes") each running the Bitbucket Server web application, behind a load balancer.

CVE-2023-43642: The SnappyInputStream was found to be vulnerable to Denial of Service (DoS) attacks when decompressing data with a too large chunk size.

Affected version:
7.21.x: prior to 7.21.21
8.12.0 to 8.12.6
8.11.0 to 8.11.6
8.10.0 to 8.10.6
8.9.x: prior to 8.9.9
8.13.x: prior to 8.13.5
8.14.x: prior to 8.14.4
8.15.x: prior to 8.15.3
8.16.x: prior to 8.16.2

QID Detection Logic(Unauthenticated):
The QID checks for vulnerable versions of Atlassian Bitbucket Server by sending a GET request to /login endpoint.


QID Detection Logic:(Authenticated)
The QID checks for vulnerable versions of Atlassian Bitbucket Server by checking the registry entry for windows and invoking commands in linux.

Note: Here, we are not checking actual version of org.xerial.snappy:snappy-java Dependency. Hence, QID set as practice.

Successful exploitation of this vulnerability allows unauthenticated attacker to expose assets in your environment susceptible to exploitation.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    The vendor has released fix for this vulnerability. Customers are advised to refer to BSERV-19100 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 379560

    Software Advisories
    Advisory ID Software Component Link
    BSERV-19100 URL Logo jira.atlassian.com/browse/BSERV-19100