Why are Tomcat CVEs in the Confluence bundle silently patched?

Hi!

According the FAQ question "What if a security problem is found in the bundled version of Tomcat?" at: https://confluence.atlassian.com/doc/end-of-support-announcements-for-confluence-210239673.html Atlassian states that "Our security team monitors vulnerabilities in all our dependencies, including Tomcat, and fixes continue to follow our Security Bugfix Policy."

However although new, patched, versions of Tomcat are included in new bundles of Confluence, no security advisories have been published or otherwise stated in the Release notes for at least the last year.

Only looking at this year, several important security vulnerabilities have been patched in Tomcat, including, but not limited to:

CVE-2016-0714:

"By placing a carefully crafted object into a session, a malicious web application could trigger the execution of arbitrary code."

CVE-2016-0706:

"[..] exposed sensitive information from other web applications, such as session IDs"

CVE-2016-0763:

"[...] read and write data owned by other web applications."

Source: https://tomcat.apache.org/security-8.html

Maybe I have misunderstood Atlassian's commitment to 3:rd party security issues?

Update 2016-08-11:

Our Atlassian Expert partner alleges that Confluence is not affected by vulnerabilities in third party software, such as for example Tomcat or the Oracle JDK.

This is a strange point of view in my opinion and if true why does Atlassian bother to update, and hence patch vulnerabilities for, third party software in the bundle?

I might of course be wrong, and if so that would be a good day for security since then we do not have to patch anymore! :)

3 answers

This widget could not be displayed.
David Black Atlassian Team Sep 13, 2016

Hi,

Atlassian aims to keep all third-party software used in our products and services up to date with the latest released versions. It is important to note that not all vulnerabilities in third party software affect Atlassian products and services. For example, CVE-2016-0714 is specifically about a flaw in Tomcat that allows an attacker to bypass intended SecurityManager restrictions, as our software currently does not use a security manager this issue does not affect our software.

The Atlassian security team monitors for vulnerabilities in our software's dependencies, including Tomcat, and fixes follow our Security Bugfix Policy. If our security team finds a vulnerability within any of our products caused by third-party software or otherwise, Atlassian addresses the issue based on our Security Bugfix Policy. If a vulnerability is of a critical severity, then we follow our Security Advisory Publishing Policy.

This widget could not be displayed.

I totally agree with you regarding CVE handling, that's why I upvoted your issue. But: Seen pragmatic this tomcat is for Confluence only. It is not ment as a shared environment. So vuls ragarding "other (malicious) webapps" are  - lets say less critical. But I don't know if that applies to the OSGI environment used by Confluence. Maybe a plugin can abuse those vulnerabilities.

This widget could not be displayed.

Yes, I think we agree here. The issue is not a specific CVE, but the handling, and silently patching of vulnerabilities - without informing whether or not a thorough vulnerability assessment has been made of each CVE and if for that reason we as customers need to update to a new Confluence bundle.

Suggest an answer

Log in or Sign up to answer
Atlassian Summit 2018

Meet the community IRL

Atlassian Summit is an excellent opportunity for in-person support, training, and networking.

Learn more
Community showcase
Published Tuesday in Confluence

Add-on evaluation with confluence templates

Atlassian market place contains number of Apps/Addons which improves the capability of out of the box Atlassian products. It is good to follow a plugin evaluation process before install add-ons. So t...

61 views 8 4
Read article

Atlassian User Groups

Connect with like-minded Atlassian users at free events near you!

Find a group

Connect with like-minded Atlassian users at free events near you!

Find my local user group

Unfortunately there are no AUG chapters near you at the moment.

Start an AUG

You're one step closer to meeting fellow Atlassian users at your local meet up. Learn more about AUGs

Groups near you