Uploaded image for project: 'Bamboo Data Center'
  1. Bamboo Data Center
  2. BAM-22280

Upgrade Tomcat to fix CVE-2023-28709

XMLWordPrintable

      Issue summary

      Apache Tomcat should be upgraded to 8.5.88 and 9.0.74 or a later version to fix CVE-2023-28709

      Environment

      • Bamboo 8, 9

      Steps to Reproduce

      • Check the Apache Tomcat version on pom.xml or <bamboo-install>/bin/version.sh/bat

      Expected Results

      • Bamboo 8.x: apache-tomcat 8.5.88 and later
      • Bamboo 9.x: apache-tomcat 9.0.74 and later

      Actual Results

      • Bamboo 8.x: apache-tomcat 8.5.87 and earlier
      • Bamboo 9.x: apache-tomcat-9.0.73 and earlier

      Workaround

      At your own risk, you can manually upgrade Tomcat as instructed on this KB:

      WARNING: Unless still reproducible on official releases, Atlassian Support may refuse support requests for Bamboo running over unofficial Tomcat versions.

              0ecd005f55dd Krzysztof Podsiadło
              73868399605e Eduardo Alvarenga
              Votes:
              2 Vote for this issue
              Watchers:
              8 Start watching this issue

                Created:
                Updated:
                Resolved: