Come for the products,
stay for the community

The Atlassian Community can help you and your team get more value out of Atlassian products and practices.

Atlassian Community about banner
Community Members
Community Events
Community Groups


Our vulnerability scanner flagged tomcat as an issue, which i believe is part of the bamboo install. 

Is there a patch? 

were are running bamboo-8.0.6



1 answer

0 votes

Hello @Miguel Gusils

If you are referring to CVE-2020-9484/CVE-2022-23181, those are being addressed by the following BAM:

Due to its nature, it is classified as internal-only.

A fix will be released in a few days with Bamboo 8.2 bundling Tomcat 8.5.75. Please keep an eye on the Bamboo release notes. You can also watch the Bamboo Announcements community page to be notified once a release is available.


Kind regards,

Eduardo Alvarenga
Atlassian Support APAC


Bamboo 8.2.1 has released but there is no description about these CVEs in the fix list.

Hello @Chihara,

As mentioned before, is an internal ticket and will not be mentioned to the public. I can confirm the fix for the CVE has been published and is available on Bamboo 8.2.1.

You can validate the embedded Tomcat version in Bamboo by following this KB:


Eduardo Alvarenga
Atlassian Support APAC

Suggest an answer

Log in or Sign up to answer
Community showcase
Published in Bamboo

Bamboo Data Center on Kubernetes

Hi, If you are running self-managed environments and looking to adopt modern infrastructure, Bamboo Data Center can now be deployed in a Kubernetes cluster. By leveraging Kubernetes, you can easily...

931 views 3 8
Read article

Community Events

Connect with like-minded Atlassian users at free events near you!

Find an event

Connect with like-minded Atlassian users at free events near you!

Unfortunately there are no Community Events near you at the moment.

Host an event

You're one step closer to meeting fellow Atlassian users at your local event. Learn more about Community Events

Events near you