ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ืŸ ื‘ื™ื˜ื‘ื•ืงืงืขื˜ ืกืขืจื•ื•ื™ืจืขืจ ืึทื– ืึทืœืึทื•ื– ืงืึธื“ ื“ื•ืจื›ืคื™ืจื•ื ื’ ืื•ื™ืฃ ื“ื™ ืกืขืจื•ื•ืขืจ

ื ืงืจื™ื˜ื™ืฉ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ (CVE-2022-36804) ืื™ื– ื™ื™ื“ืขื ืึทืคื™ื™ื“ ืื™ืŸ Bitbucket Server, ืึท ืคึผืขืงืœ ืคึฟืึทืจ ื“ื™ืคึผืœื•ื™ื™ื ื’ ืึท ื•ื•ืขื‘ ืฆื•ื‘ื™ื ื“ ืคึฟืึทืจ ืืจื‘ืขื˜ืŸ ืžื™ื˜ ื’ื™ื˜ ืจื™ืคึผืึทื–ืึทื˜ืึธืจื™ื–, ื•ื•ืึธืก ืึทืœืึทื•ื– ืึท ื•ื•ื™ื™ึทื˜ ืึทื˜ืึทืงืขืจ ืžื™ื˜ ืœื™ื™ืขื ืขืŸ ืึทืงืกืขืก ืฆื• ืคึผืจื™ื•ื•ืึทื˜ ืึธื“ืขืจ ืขืคื ื˜ืœืขืš ืจื™ืคึผืึทื–ืึทื˜ืึธืจื™ื– ืฆื• ื•ื™ืกืคื™ืจืŸ ืึทืจื‘ื™ื˜ืจืึทืจื™ืฉ ืงืึธื“ ืื•ื™ืฃ ื“ื™ ืกืขืจื•ื•ืขืจ. ื“ื•ืจืš ืฉื™ืงื˜ ื’ืขืขื ื“ื™ืงื˜ ื”ื˜ื˜ืคึผ ื‘ืขื˜ืŸ. ื“ื™ ืึทืจื•ื™ืกื’ืขื‘ืŸ ืื™ื– ื’ืขื•ื•ืขืŸ ืคืึธืจืฉื˜ืขืœืŸ ื–ื™ื ื˜ ื•ื•ืขืจืกื™ืข 6.10.17 ืื•ืŸ ืื™ื– ืกืึทืœื•ื•ื“ ืื™ืŸ ื‘ื™ื˜ื‘ื•ืงืงืขื˜ ืกืขืจื•ื•ื™ืจืขืจ ืื•ืŸ ื‘ื™ื˜ื‘ื•ืงืงืขื˜ ื“ืึทื˜ืึท ืฆืขื ื˜ืขืจ ืจื™ืœื™ืกื™ื– 7.6.17, 7.17.10, 7.21.4, 8.0.3, 8.2.2, ืื•ืŸ 8.3.1. ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืงืขืŸ ื ื™ืฉื˜ ื“ืขืจืฉื™ื™ึทื ืขืŸ ืื™ืŸ ื“ื™ bitbucket.org ื•ื•ืึธืœืงืŸ ื“ื™ื ืกื˜, ืึธื‘ืขืจ ื‘ืœื•ื™ื– ืึทืคืขืงืฅ ืคึผืจืึธื“ื•ืงื˜ืŸ ื•ื•ืึธืก ื–ืขื ืขืŸ ืื™ื ืกื˜ืึทืœื™ืจืŸ ืื•ื™ืฃ ื–ื™ื™ืขืจ ืœืึธืงืึทืœ.

ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ื– ื’ืขื•ื•ืขืŸ ื™ื™ื“ืขื ืึทืคื™ื™ื“ ื“ื•ืจืš ืึท ื–ื™ื›ืขืจื”ื™ื™ื˜ ืคืึธืจืฉืขืจ ื•ื•ื™ ืึท ื˜ื™ื™ืœ ืคื•ืŸ ื“ื™ Bugcrowd Bug Bounty ืื™ื ื™ืฆื™ืื˜ื™ื•ื•, ื•ื•ืึธืก ื’ื™ื˜ ืจื™ื•ื•ืึธืจื“ื– ืคึฟืึทืจ ื™ื“ืขื ื˜ื™ืคื™ื™ื ื’ ื‘ื™ื– ืึทื”ืขืจ ืื•ืžื‘ืึทืงืึทื ื˜ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื–. ื“ื™ ื‘ืึทืœื•ื™ื ื•ื ื’ ืื™ื– ื’ืขื•ื•ืขืŸ 6 ื˜ื•ื™ื–ื ื˜ ื“ืึธืœืœืึทืจืก. ื“ืขื˜ืึทื™ืœืก ื•ื•ืขื’ืŸ ื“ื™ ื‘ืึทืคืึทืœืŸ ืื•ืคึฟืŸ ืื•ืŸ ื“ื™ ืคึผืจืึธื•ื˜ืึทื˜ื™ื™ืคึผ ื–ืขื ืขืŸ ืฆื•ื’ืขื–ืื’ื˜ ืฆื• ื–ื™ื™ืŸ ื’ื™ืœื•ื™ 30 ื˜ืขื’ ื ืึธืš ื“ื™ ืœืึทื˜ืข ืื™ื– ืืจื•ื™ืก. ื•ื•ื™ ืึท ืžืึธืก ืฆื• ืจืขื“ื•ืฆื™ืจืŸ ื“ื™ ืจื™ื–ื™ืงื™ืจืŸ ืคื•ืŸ ืึท ื‘ืึทืคืึทืœืŸ ืื•ื™ืฃ ื“ื™ื™ืŸ ืกื™ืกื˜ืขืžืขืŸ ืื™ื™ื“ืขืจ ืึทืคึผืœื™ื™ื™ื ื’ ื“ื™ ืœืึทื˜ืข, ืขืก ืื™ื– ืจืขืงืึทืžืขื ื“ื™ื“ ืฆื• ื‘ืึทื’ืจืขื ืขืฆืŸ ืฆื™ื‘ื•ืจ ืึทืงืกืขืก ืฆื• ื“ื™ ืจื™ืคึผืึทื–ืึทื˜ืึธืจื™ื– ื ื™ืฆืŸ ื“ื™ "feature.public.access=false" ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’