Uploaded image for project: 'Bamboo Data Center'
  1. Bamboo Data Center
  2. BAM-22026

Upgrade Apache Tomcat to mitigate CVE-2022-42252 on Bamboo 8.x

    XMLWordPrintable

Details

    Description

      Issue Summary

      This is reproducible in Data Center:

      On Bamboo 8, Apache Tomcat should be upgraded to version 8.5.83 or later to mitigate CVE-2022-42252

      Environment

      Bamboo 8.0, 8.1, 8.2

      Steps to Reproduce

      1. Check Tomcat version on pom.xml or <bamboo-install>/bin/version.sh/bat

      Expected Results

      apache-tomcat 8.5.83+ is expected

      Actual Results

      apache-tomcat 8.5.82 or earlier is in use

      Workaround

      As stated in the CVE-2022-42252 announcement, either:

      WARNING: Unless still reproducible on official releases, Atlassian Support may refuse support requests for Bamboo running over unofficial Tomcat versions.

      Note

      Bamboo version 9 is NOT VULNERABLE to the issue as rejectIllegalHeader is set to true by default.

      Attachments

        Issue Links

          Activity

            People

              mgardias Marcin Gardias
              73868399605e Eduardo Alvarenga
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: