Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Confluence with Tomcat 6 web server on windows got security issue

Jonatan Bouillon April 17, 2019

 

I have a confluence server on windows with version 5.3.4 and I realize this week that it works with Tomcat 6.0.X.

And Tomcat 6.0.X got an security issue and it's not supported by confluence. We got hack this week.

I can see that the last version of tomcat 7, 8, 9 got the fix for the sercurity issue but there is no update for version 6.

  • Fix for CVE-2019-0232, an RCE vulnerability on Windows

I know that this version of confluence is deprecated and I should upgrade but i'm wondering if there is an alternative to using tomcat with confluence or I really need to upgrade?

1 answer

1 accepted

0 votes
Answer accepted
JP _AC Bielefeld Leader_
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
April 17, 2019

You need to upgrade, sorry! 

Jonatan Bouillon April 17, 2019

Thanks for the answer.

If I upgrade, the problem seem to be present in the new version of confluence because it's not using the last version of tomcat.

Do you know if I can upgrade tomcat separatly to get the version 9.0.19 of Apache Tomcat that fix the issue. 

I know I should upgrade or go to the cloud anyway because my version is deprecate.

Daniel Eads
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
April 18, 2019

Hi Jonatan,

We don't recommend trying to upgrade Tomcat separately from Confluence. While the most recent Confluence release (6.15.2) bundles Tomcat 9.0.12, the default setup of Tomcat that Confluence ships with is not in a state that is affected by CVE-2019-0232.

It is possible that the Tomcat setup could be affected, but only if particular features are manually enabled in the server.xml file. This would be an advanced and deliberate change an administrator would need to do. The default setup we provide is not affected under the details of the vulnerability.

Cheers,
Daniel

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events