Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Apache Tomcat in JIRA

Janaki Lenagala January 30, 2022

I am new to JIRA and Open Source Software. We are using Apache Tomcat in our JIRA server and version is 8.5.72.

May I know what is the purpose of using Apache Tomcat server in JIRA? 

How do we configure it?  is it configured to persist sessions using the FileStore?

May I know how CVE-2022-2318 is affects to Jira system which used Apache tomcat ?

 

2 answers

1 vote
Daniel Eads
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
January 31, 2022

Hi @Janaki Lenagala ,

Atlassian's security team is evaluating CVE-2022-23181, which was released by the Apache foundation four days ago . Apache's initial severity listing on their mailing list is low. The public issue related to Atlassian's investigation for Jira is JRASERVER-73223 , which you can watch for updates.

Cheers,
Daniel

0 votes
Pramodh M
Community Champion
January 30, 2022

Hi @Janaki Lenagala 

Apache Tomcat is bundled along with Applications (Jira, Confluence, Bitbucket) 

Here are version references for the same

https://confluence.atlassian.com/jiracore/bundled-tomcat-and-java-versions-1013854250.html

FAQ regarding the same

https://confluence.atlassian.com/kb/faq-for-cve-2021-44228-1103069406.html

Thanks,
Pramodh

Janaki Lenagala January 30, 2022

Thank you for the reply. 

CVE-2022-23181 is not listed in the above vulnerability list. 

How do we find whether JIRA is vulnerable to CVE-2022-23181 ?

Suggest an answer

Log in or Sign up to answer