Lucene search

K
atlassian[email protected]JRASERVER-72310
HistoryApr 12, 2021 - 3:50 p.m.

8.5 and 8.13 LTS releases should bundle Tomcat 8.5.63 or higher

2021-04-1215:50:10
jira.atlassian.com
19
apache tomcat
lts release
upgrade

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.002

Percentile

60.0%

h3. Issue Summary
The Apache Tomcat version used by the currently available LTS (Long Term Support) releases has a few vulnerabilities, therefore the next LTS release should bundle an updated version of Tomcat.

h3. Steps to Reproduce

Not applicable.

h3. Expected Results

  • Not applicable.

h3. Actual Results

  • Not applicable.

h3. Note on fix
Tomcat version will be bumped to version [8.5.65|https://tomcat.apache.org/tomcat-8.5-doc/changelog.html]

h3. Workaround

Affected configurations

Vulners
Node
atlassianjira_data_centerRange8.5.12
OR
atlassianjira_data_centerRange8.13.5
OR
atlassianjira_data_centerRange8.16.0
OR
atlassianjira_data_centerRange<8.5.16
OR
atlassianjira_data_centerRange<8.13.8
VendorProductVersionCPE
atlassianjira_data_center*cpe:2.3:a:atlassian:jira_data_center:*:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.002

Percentile

60.0%