Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

Earn badges and make progress

You're on your way to the next level! Join the Kudos program to earn points and save your progress.

Deleted user Avatar
Deleted user

Level 1: Seed

25 / 150 points

Next: Root


1 badge earned


Participate in fun challenges

Challenges come and go, but your rewards stay with you. Do more to earn more!


Gift kudos to your peers

What goes around comes around! Share the love by gifting kudos to your peers.


Rise up in the ranks

Keep earning points to reach the top of the leaderboard. It resets every quarter so you always have a chance!


Come for the products,
stay for the community

The Atlassian Community can help you and your team get more value out of Atlassian products and practices.

Atlassian Community about banner
Community Members
Community Events
Community Groups


Our vulnerability scanner flagged tomcat as an issue, which i believe is part of the bamboo install. 

Is there a patch? 

were are running bamboo-8.0.6



1 answer

0 votes

Hello @Miguel Gusils

If you are referring to CVE-2020-9484/CVE-2022-23181, those are being addressed by the following BAM:

Due to its nature, it is classified as internal-only.

A fix will be released in a few days with Bamboo 8.2 bundling Tomcat 8.5.75. Please keep an eye on the Bamboo release notes. You can also watch the Bamboo Announcements community page to be notified once a release is available.


Kind regards,

Eduardo Alvarenga
Atlassian Support APAC


Bamboo 8.2.1 has released but there is no description about these CVEs in the fix list.

Hello @Chihara,

As mentioned before, is an internal ticket and will not be mentioned to the public. I can confirm the fix for the CVE has been published and is available on Bamboo 8.2.1.

You can validate the embedded Tomcat version in Bamboo by following this KB:


Eduardo Alvarenga
Atlassian Support APAC

Suggest an answer

Log in or Sign up to answer

Atlassian Community Events