Tomcat versions bundled with the Crowd product are vulnerable to CVE-2021-33037

XMLWordPrintable

    • 5.3
    • Medium
    • CVE-2021-33037

      The different Tomcat versions (8.5.X) bundled to the Atlassian Crowd product versions lower than Crowd 4.4.1 are vulnerable to CVE-2021-33037

      The Tomcat versions from 8.5.0 to 8.5.66 are affected by the mentioned CVE-2021-33037 and some of the versions in this range are bundled to the Atlassian Crowd product versions lower than Crowd 4.4.1.

       

      It is important to note that the Atlasian Crowd versions 4.4.1 and 5.0.0 were bundled to Tomcat 8.5.72 as this Tomcat version is not affected by CVE-2021-33037

            Assignee:
            Unassigned
            Reporter:
            Security Metrics Bot
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: