Lucene search

K
atlassian73868399605eBAM-22330
HistoryJun 26, 2023 - 7:32 a.m.

Upgrade Tomcat to fix CVE-2023-34981

2023-06-2607:32:46
73868399605e
jira.atlassian.com
18
apache tomcat
upgrade
version 9.0.75
cve-2023-34981
bamboo 9
informational ticket

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

0.007 Low

EPSS

Percentile

79.9%

h3. Issue Summary

Apache Tomcat should be upgraded to 9.0.75+ or a later version to fix [CVE-2023-34981|https://nvd.nist.gov/vuln/detail/CVE-2023-34981]
{panel:bgColor=#e3fcef}
Bamboo is not vulnerable to this issue as it does not bundle Apache Tomcat 9.0.74 on any of its releases.

This is an informational ticket to inform customers about the underlying CVE.
{panel}
h3. Environment

  • Bamboo 9

h3. Steps to Reproduce

  • Check the Apache Tomcat version onΒ {{pom.xml}}Β orΒ {{<bamboo-install>/bin/version.sh/bat}}

h3. Expected Results

  • Bamboo 9.x: apache-tomcat 9.0.75 or later

h3. Actual Results

  • Bamboo 9.x: apache-tomcat 9.0.74

Affected configurations

Vulners
Node
atlassianbamboo_data_centerRange≀n/a
OR
atlassianbamboo_data_centerRange<9.3.1
OR
atlassianbamboo_data_centerRange<9.2.4

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

0.007 Low

EPSS

Percentile

79.9%