Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Apache Tomcat upgrade for 8.5.42

Sadath Ali Syed May 21, 2020

Team,

We are currently using Jira Server Enterprise version 8.5.3. The bundled version of Apache Tomcat is 8.5.42. This version of Apache Tomcat is vulnerable. We read that the exploit is only possible if we are using an AJP connector, not the regular HTTP connector that is used by default in Jira.

However, we want to upgrade Apache tomcat version. Can someone please let us know if there will be issues if we upgrade Apache tomcat version. Also, can someone provide us the details on how to upgrade the bundled Apache tomcat version.

1 answer

0 votes
JP _AC Bielefeld Leader_
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
May 23, 2020

Hi,

what connector are you using. As long as the default connector is used & the AJP connector is disabled in server.xml, you're fine. Even with AJP there is now a mandatory security switch to only allow authorized AJP clients (eg. Apache HTTPD) access to the AJP connector.

Nevertheless, there is no guarantee that an upgraded Tomcat server will run with Jira. I would stay with the bundled one & check my Tomcat configuration to tighten up security.

Best

JP

RianS
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
June 1, 2020

I have been looking at the vulnerabilities and the Atlassian documentation doesn't give much guidance if you rely on AJP for functionality. Do you have a link to the additional documentation on this security switch for AJP?

JP _AC Bielefeld Leader_
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
June 1, 2020

Sure,

https://tomcat.apache.org/tomcat-8.5-doc/config/ajp.html

A simple google on tomcat 8.5 AJP would have done.

Best

JP

Suggest an answer

Log in or Sign up to answer