Lucene search

K
atlassian0d90b409cb18BSERV-14130
HistoryJun 09, 2023 - 1:54 a.m.

Apache Tomcat CVE-2023-28709

2023-06-0901:54:09
0d90b409cb18
jira.atlassian.com
175
apache tomcat
bitbucket
upgrade
vulnerability

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.007 Low

EPSS

Percentile

79.9%

h3. Issue summary

Apache Tomcat should be upgraded to 9.0.74 or a later version to fix [CVE-2023-28709|https://nvd.nist.gov/vuln/detail/CVE-2023-28709]
h3. Environment

  • Bitbucket 8.10.x and 8.11

h3. Steps to Reproduce

  • Check the Apache Tomcat version onΒ {{pom.xml}}

h3. Expected Results

  • Bitbucket 8.10 and 8.11: apache-tomcat 9.0.74 and later

h3. Actual Results

  • Bitbucket 8.10: apache-tomcat-9.0.73 and earlier
  • Bitbucket 8.11: apache-tomcat-9.0.73 and earlier

Affected configurations

Vulners
Node
atlassianbitbucket_data_centerRange≀7.17.18
OR
atlassianbitbucket_data_centerRange≀7.21.7
OR
atlassianbitbucket_data_centerRange≀8.10.0
OR
atlassianbitbucket_data_centerRange≀8.11.0
OR
atlassianbitbucket_data_centerRange<7.17.19
OR
atlassianbitbucket_data_centerRange<7.21.15
OR
atlassianbitbucket_data_centerRange<8.8.7
OR
atlassianbitbucket_data_centerRange<8.9.4
OR
atlassianbitbucket_data_centerRange<8.10.4
OR
atlassianbitbucket_data_centerRange<8.11.3
OR
atlassianbitbucket_data_centerRange<8.12.1
OR
atlassianbitbucket_data_centerRange<8.13.0

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.007 Low

EPSS

Percentile

79.9%