Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

tomcat

Miguel Gusils
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
March 29, 2022

Hi 

Our vulnerability scanner flagged tomcat as an issue, which i believe is part of the bamboo install. 

Is there a patch? 

were are running bamboo-8.0.6

thanks,

-mg

1 answer

0 votes
Eduardo Alvarenga
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
March 29, 2022

Hello @Miguel Gusils

If you are referring to CVE-2020-9484/CVE-2022-23181, those are being addressed by the following BAM:

Due to its nature, it is classified as internal-only.

A fix will be released in a few days with Bamboo 8.2 bundling Tomcat 8.5.75. Please keep an eye on the Bamboo release notes. You can also watch the Bamboo Announcements community page to be notified once a release is available.

 

Kind regards,

Eduardo Alvarenga
Atlassian Support APAC

Chihara
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
April 25, 2022

Eduardo,

Bamboo 8.2.1 has released but there is no description about these CVEs in the fix list.

Eduardo Alvarenga
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
April 25, 2022

Hello @Chihara,

As mentioned before, https://jira.atlassian.com/browse/BAM-21603 is an internal ticket and will not be mentioned to the public. I can confirm the fix for the CVE has been published and is available on Bamboo 8.2.1.

You can validate the embedded Tomcat version in Bamboo by following this KB:

Cheers,

Eduardo Alvarenga
Atlassian Support APAC

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events