Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

CVE-2022-42252 Apache Tomcat - Request Smuggling mitigation

act rang
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
March 1, 2023

[SECURITY] CVE-2022-42252 Apache Tomcat - Request Smuggling-Apache Mail Archives

 

Base on the above security bulletin from Apache.org, one of the mitigating factor is to "ensure rejectillegalheader is set to true".

 

How do we insert that into server.xml?

 

Thank you,

AR

1 answer

0 votes
Pavel Junek
Community Champion
March 1, 2023

Hi @act rang,

Welcome to Atlassian community!

Which Jira Server / Data Center version are you using? 

You can then check here which version of Tomcat your Jira has. It looks like Atlassian doesn't even see this issue for Jira (there are only tickets for Confluence and Bamboo). 

For exact settings, I recommend contacting Atlassian support, who will advise you on what exactly to do (you will be sure that Jira will work).

Pavel

Suggest an answer

Log in or Sign up to answer