Current version of Tomcat 8.0.33 is vulernable to http://www.cvedetails.com/cve/CVE-2016-3092/

      We need to upgrade the version we package with JIRA to address that vulnerability.

            [JRASERVER-61885] Upgrade Tomcat to 8.0.36 or later

            Andy Heinzer made changes -
            Component/s New: Tomcat [ 56390 ]
            Bugfix Automation Bot made changes -
            Minimum Version New: 7.01
            Owen made changes -
            Workflow Original: JAC Bug Workflow v2 [ 2835147 ] New: JAC Bug Workflow v3 [ 2914249 ]
            Status Original: Resolved [ 5 ] New: Closed [ 6 ]
            Owen made changes -
            Workflow Original: JIRA Bug Workflow w Kanban v7 - Restricted [ 2561125 ] New: JAC Bug Workflow v2 [ 2835147 ]
            Kamil Kolonko made changes -
            Affects Version/s New: 7.1.9 [ 64205 ]
            Affects Version/s Original: 7.1.9 Server [ 62034 ]
            nma (Inactive) made changes -
            Labels Original: affects-server cvss-high denial-of-service exclude-from-security-metrics-page security New: affects-server cvss-high denial-of-service exclude-from-security-metrics-page patch-management security
            Ignat (Inactive) made changes -
            Workflow Original: JIRA Bug Workflow w Kanban v6 - Restricted [ 1590053 ] New: JIRA Bug Workflow w Kanban v7 - Restricted [ 2561125 ]
            David Black made changes -
            Security Original: Reporter and Atlassian Staff [ 10751 ]
            David Black made changes -
            Link New: This issue is related to JRA-63726 [ JRA-63726 ]
            Ignat (Inactive) made changes -
            Link New: This issue is related to JRA-63413 [ JRA-63413 ]

              morzechowski Michal Orzechowski (Inactive)
              46d40de8a721 Joel E. Wilson
              Affected customers:
              4 This affects my team
              Watchers:
              6 Start watching this issue

                Created:
                Updated:
                Resolved: