Hi Guys,
Newbie here involved in my first Confluence deployment for a very large US company. Please be gentle.
We recently downloaded and installed the 3.5.13 release of Confluence. Tomcat 6.0.32 was bundled with it. The head of IT Security at our company identified 4 security vulnerabilities with that release of Tomcat. 3 of these are fixed in Tomcat 6.0.33. The other and most critical one is CVE-2011-3190. This vulnerability looks to be addressed in a "not-yet-released" version of Tomcat 6.0.34. So the fact that a specific release of Tomcat was bundled with Confluence raises some questions about if and when we apply patches or upgrades to Tomcat:
- What is the risk (if any) I take if I apply a release update or patch to Tomcat without also upgrading Confluence? In other words, can I go to Tomcat 6.0.33 and then 6.0.34 independent of an increase in the Confluence 3.5 line?
- How fast does Atlassian typically turnaround a new release of Confluence to incorporate Tomcat release changes, especially when a critical security vulnerability is in play?
I need to provide our Security Leader assurances that we will be able to address these vulnerabilities in a timely manner, so any insight anyone has or can point me to is greatly appreciated.