Tomcat versions bundled with the Crowd product are vulnerable to CVE-2021-33037

XMLWordPrintable

    • 5.3
    • Medium
    • CVE-2021-33037

      The different Tomcat versions (8.5.X) bundled to the Atlassian Crowd product versions lower than Crowd 4.4.1 are vulnerable to CVE-2021-33037

      The Tomcat versions from 8.5.0 to 8.5.66 are affected by the mentioned CVE-2021-33037 and some of the versions in this range are bundled to the Atlassian Crowd product versions lower than Crowd 4.4.1.

       

      It is important to note that the Atlasian Crowd versions 4.4.1 and 5.0.0 were bundled to Tomcat 8.5.72 as this Tomcat version is not affected by CVE-2021-33037

              Assignee:
              Unassigned
              Reporter:
              Security Metrics Bot
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: