Lucene search

K
atlassian[email protected]JRASERVER-71321
HistoryJul 17, 2020 - 3:19 p.m.

Upgrade the bundled version of Apache Tomcat to 8.5.57

2020-07-1715:19:11
jira.atlassian.com
24

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.922 High

EPSS

Percentile

99.0%

h3. Issue Summary

The recently disclosed vulnerability regarding Apache Tomcat

affects the following versions:

Apache Tomcat 8.x from 8.5.1 to 8.5.56
Apache Tomcat 9.x from 9.0.0.M5 to 9.0.36
Apache Tomcat 10.x from 10.0.0-M1 to 10.0.0-M6

Additionally, the following disclosed vulnerability regarding Tomcat:

affects the following versions:

Apache Tomcat 7.x from 7.0.27 to 7.0.104
Apache Tomcat 8.x from 8.5.1 to 8.5.56
Apache Tomcat 9.x from 9.0.0.M5 to 9.0.36
Apache Tomcat 10.x from 10.0.0-M1 to 10.0.0-M6

We should bundle a more recent version of Tomcat so that Jira is not affected by this in the future.

h3. Steps to Reproduce

h3. Expected Results

  • Not applicable.

h3. Actual Results

  • Not applicable.

h3. Workaround

Affected configurations

Vulners
Node
atlassianjira_data_centerRange8.11.0
OR
atlassianjira_data_centerRange8.12.0
OR
atlassianjira_data_centerRange8.5.8
OR
atlassianjira_data_centerRange<8.12.1
OR
atlassianjira_data_centerRange<8.13.0-EAP
OR
atlassianjira_data_centerRange<8.13.0
OR
atlassianjira_data_centerRange<8.5.9
OR
atlassianjira_data_centerRange<8.14.0
OR
atlassianjira_data_centerRange<8.14.1

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.922 High

EPSS

Percentile

99.0%