This is reproducible on Data Center: yes

      Steps to Reproduce

      1. -

      Expected Results

      -

      Actual Results

      -

      Workaround

      Manually updating Tomcat would be a valid workaround, however, checking the Tomcat download link we can see that the latest available version is

      Opening a ticket to keep track of it on our side.

      [Update from Jul 21, 2022]
      Tomcat released the 9.0.65 version which contains the fix for this vulnerability (CVE-2022-34305):

          Form Name

            [CONFSERVER-79480] Confluence Apache Tomcat CVE-2022-34305

            During a recent review of a Confluence 7.13.7 installation, we noted one page returned an Apache Tomcat 9.0.63 banner. 7.13.7 is not listed as an impacted version in this issue, however. Apologies if I missed it, but did Atlassian ever confirm if any versions prior to 7.13.8 were impacted by this issue?

            Aslan Konsavage added a comment - During a recent review of a Confluence 7.13.7 installation, we noted one page returned an Apache Tomcat 9.0.63 banner. 7.13.7 is not listed as an impacted version in this issue, however. Apologies if I missed it, but did Atlassian ever confirm if any versions prior to 7.13.8 were impacted by this issue?

            A fix for this issue is available in Confluence Server and Data Center 7.13.11.
            Upgrade now or check out the Release Notes to see what other issues are resolved.

            Madhubabu Kethineni (Inactive) added a comment - A fix for this issue is available in Confluence Server and Data Center 7.13.11. Upgrade now or check out the Release Notes to see what other issues are resolved.

            James Whitehead added a comment - - edited

            Hi 7675e03adf45,
            This fix will in fact be re-released with the availability of 7.13.11.
            The fix version on this ticket will be updated once the new release has been made available.
            We are expediting the new release but we still have to follow our standard quality processes. We are targeting a release for Tuesday 25th October so long as everything goes to plan. All customers will be notified on this ticket with a comment once the new release has been made available.
            Cheers.

            James Whitehead added a comment - - edited Hi 7675e03adf45 , This fix will in fact be re-released with the availability of 7.13.11. The fix version on this ticket will be updated once the new release has been made available. We are expediting the new release but we still have to follow our standard quality processes. We are targeting a release for Tuesday 25th October so long as everything goes to plan. All customers will be notified on this ticket with a comment once the new release has been made available. Cheers.

            Rick Carini added a comment - - edited

            Hi jwhitehead@atlassian.com,

            With the pulling of 7.13.10, will this be re-released into 7.13.11?

            Is there a current ETA for 7.13.11?

            Thanks once again!

            Regards,
            Rick

            Rick Carini added a comment - - edited Hi jwhitehead@atlassian.com , With the pulling of 7.13.10, will this be re-released into 7.13.11? Is there a current ETA for 7.13.11? Thanks once again! Regards, Rick

            I would assume that it probably affects all previous versions

            Richard Bukovansky added a comment - I would assume that it probably affects all previous versions

            Rick Carini added a comment - - edited

            Hi jwhitehead@atlassian.com,

            Does this issue only impact 7.13.8 or is it impacting all previous versions of 7.13.x?
            (as Richard mentioned above?)

            Regards,
            Rick

            Rick Carini added a comment - - edited Hi jwhitehead@atlassian.com , Does this issue only impact 7.13.8 or is it impacting all previous versions of 7.13.x? (as Richard mentioned above?) Regards, Rick

            A fix for this issue is available in Confluence Server and Data Center 7.13.10.
            Upgrade now or check out the Release Notes to see what other issues are resolved.

            James Whitehead added a comment - A fix for this issue is available in Confluence Server and Data Center 7.13.10. Upgrade now or check out the Release Notes to see what other issues are resolved.

            A fix for this issue is available in Confluence Server and Data Center 7.20.0.
            Upgrade now or check out the Release Notes to see what other issues are resolved.

            James Whitehead added a comment - A fix for this issue is available in Confluence Server and Data Center 7.20.0. Upgrade now or check out the Release Notes to see what other issues are resolved.

            Hi,
            If this has been found in 7.13.8, where there is no mention of which 7.13.x version, is this going to be fixed in as well?

            Thanks,
            Richard Bukovansky | CommerzBank AG

            Richard Bukovansky added a comment - Hi, If this has been found in 7.13.8, where there is no mention of which 7.13.x version, is this going to be fixed in as well? Thanks, Richard Bukovansky | CommerzBank AG

            A fix for this issue is available in Confluence Server and Data Center 7.19.2.
            Upgrade now or check out the Release Notes to see what other issues are resolved.

            Saran Babu Pannuru (Inactive) added a comment - A fix for this issue is available in Confluence Server and Data Center 7.19.2. Upgrade  now or check out the  Release Notes  to see what other issues are resolved.

              91133f5e20e4 Lokesh Nerella (Inactive)
              dhowell@atlassian.com Derek Howell
              Affected customers:
              6 This affects my team
              Watchers:
              23 Start watching this issue

                Created:
                Updated:
                Resolved: