We are using jira 8.13.18 server edittion of jira.
which intern uses 8.5.72 tomcat.
Are we affected ? should we upgrade to the corresponding LTS version.
Below is the explanation regarding the CVE for reference.
as per the CVE
CVE-2022-25762 Apache Tomcat - Request Mix-up
Severity: High
Vendor: The Apache Software Foundation
Versions Affected:
Apache Tomcat 9.0.0.M1 to 9.0.20
Apache Tomcat 8.5.0 to 8.5.75
Description:
If a web application sends a WebSocket message concurrently with the WebSocket connection closing, it is possible that the application will continue to use the socket after it has been closed. The error handling triggered in this case could cause the a pooled object to be placed in the pool twice. This could result in subsequent connections using the same object concurrently which could result in data being returned to the wrong use and/or other errors.
Mitigation:
Users of the affected versions should apply one of the following
mitigations:
- Upgrade to Apache Tomcat 9.0.21 or later
- Upgrade to Apache Tomcat 8.5.76 or later
https://confluence.atlassian.com/kb/faq-for-cve-2022-22965-1115149136.html Atlassian is still looking into it. But based on the products completed in research it is not. This link will most likely be updated when needed.
Best,
Clark
> https://confluence.atlassian.com/kb/faq-for-cve-2022-22965-1115149136.html
This looks like a different CVE.
The one OP has linked is related to a Tomcat vulnerability.
https://lists.apache.org/thread/6ckmjfb1k61dyzkto9vm2k5jvt4o7w7c
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-25762
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Update to Jira 8.20.8 updates Tomcat to 8.5.78 (not affected version)
https://jira.atlassian.com/browse/JRASERVER-73773
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.