Uploaded image for project: 'Bamboo Data Center'
  1. Bamboo Data Center
  2. BAM-21769

Upgrade Tomcat to mitigate CVE-2022-29885

XMLWordPrintable

      Issue summary

      Apache Tomcat should be upgraded to 8.5.79 or a superior version to fix CVE-2022-29885

      Environment

      Bamboo 7, 8

      Steps to Reproduce

      1. Check tomcat version on pom.xml or <bamboo-install>/bin/version.sh/bat

      Expected Results

      apache-tomcat 8.5.79+ is  expected

      Actual Results

      apache-tomcat 8.5.78 (or older) is used

      Workaround

      At your own risk, you can manually upgrade Tomcat as instructed on this KB:

      WARNING: Unless still reproducible on official releases, Atlassian Support may refuse support requests for Bamboo running over unofficial Tomcat versions.

              mgardias Marcin Gardias
              73868399605e Eduardo Alvarenga (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated:
                Resolved: