Current version of Tomcat 8.0.33 is vulernable to http://www.cvedetails.com/cve/CVE-2016-3092/

      We need to upgrade the version we package with JIRA to address that vulnerability.

            [JRASERVER-61885] Upgrade Tomcat to 8.0.36 or later

            Is there any idea when this will be released?

            Joel E. Wilson added a comment - Is there any idea when this will be released?

            tanga they don't usually match up.

            David Black added a comment - tanga they don't usually match up.

            Just out of curiosity, what does the Due Date in your JIRA system equate to as far as release dates?

            Joel E. Wilson added a comment - Just out of curiosity, what does the Due Date in your JIRA system equate to as far as release dates?

            David Black added a comment - - edited

            CVSS v3 score: 7.5 => High severity

            Exploitability Metrics

            Attack Vector Network
            Attack Complexity Low
            Privileges Required None
            User Interaction None

            Scope Metric

            Scope Unchanged

            Impact Metrics

            Confidentiality None
            Integrity None
            Availability High

            See http://go.atlassian.com/cvss for more details.

            David Black added a comment - - edited CVSS v3 score: 7.5 => High severity Exploitability Metrics Attack Vector Network Attack Complexity Low Privileges Required None User Interaction None Scope Metric Scope Unchanged Impact Metrics Confidentiality None Integrity None Availability High See http://go.atlassian.com/cvss for more details.

              morzechowski Michal Orzechowski (Inactive)
              46d40de8a721 Joel E. Wilson
              Affected customers:
              4 This affects my team
              Watchers:
              6 Start watching this issue

                Created:
                Updated:
                Resolved: