Lucene search

K
atlassian73868399605eBAM-22280
HistoryJun 06, 2023 - 2:52 a.m.

Upgrade Tomcat to fix CVE-2023-28709

2023-06-0602:52:01
73868399605e
jira.atlassian.com
122
apache tomcat
upgrade
cve-2023-28709
security
bamboo 8
bamboo 9

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.007

Percentile

79.9%

h3. Issue summary

Apache Tomcat should be upgraded to 8.5.88 and 9.0.74 or a later version to fix [CVE-2023-28709|https://nvd.nist.gov/vuln/detail/CVE-2023-28709]
h3. Environment

  • Bamboo 8, 9

h3. Steps to Reproduce

  • Check the Apache Tomcat version on {{pom.xml}} or {{<bamboo-install>/bin/version.sh/bat}}

h3. Expected Results

  • Bamboo 8.x: apache-tomcat 8.5.88 and later
  • Bamboo 9.x: apache-tomcat 9.0.74 and later

h3. Actual Results

  • Bamboo 8.x: apache-tomcat 8.5.87 and earlier
  • Bamboo 9.x: apache-tomcat-9.0.73 and earlier

h3. Workaround

At your own risk, you can manually upgrade Tomcat as instructed on this KB:

{}WARNING{}: Unless still reproducible on official releases, Atlassian Support may refuse support requests for Bamboo running over unofficial Tomcat versions.

Affected configurations

Vulners
Node
atlassianbamboo_data_centerRange9.0.2
OR
atlassianbamboo_data_centerRange9.3.0
OR
atlassianbamboo_data_centerRange9.1.1
OR
atlassianbamboo_data_centerRange9.2.1
OR
atlassianbamboo_data_centerRange9.1.2
OR
atlassianbamboo_data_centerRange8.2.8
OR
atlassianbamboo_data_centerRange9.0.3
OR
atlassianbamboo_data_centerRange8.1.12
OR
atlassianbamboo_data_centerRange9.2.3
OR
atlassianbamboo_data_centerRange9.1.3
OR
atlassianbamboo_data_centerRange9.0.4
OR
atlassianbamboo_data_centerRange8.2.9
OR
atlassianbamboo_data_centerRange<9.3.1
OR
atlassianbamboo_data_centerRange<9.2.4
VendorProductVersionCPE
atlassianbamboo_data_center*cpe:2.3:a:atlassian:bamboo_data_center:*:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.007

Percentile

79.9%