-
Bug
-
Resolution: Fixed
-
Medium (View bug fix roadmap)
-
8.6.1
-
8.06
-
29
-
Severity 2 - Major
-
611
-
Issue Summary
The recently disclosed vulnerabilities regarding Apache Tomcat
Which affects the following versions:
- Apache Tomcat 8.x from 8.5.0 before 8.5.50
We should bundle a more recent version of Tomcat so that Jira is not affected by this in the future.
Steps to Reproduce
- Not applicable.
Expected Results
- Not applicable.
Actual Results
- Not applicable.
Workaround
- Manually upgrade Tomcat according to our documentation.
- details
-
JRASERVER-70727 Documentation on configuring Jira Server with Apache AJP should note recent Ghost Cat CVE-2020-1938
- Closed
-
JSDSERVER-6768 Jira Service Desk Security Vulnerability Tomcat AJP CNVD-2020-10487/CVE-2020-1938
- Closed
- is related to
-
JRASERVER-70993 The version of Apache Tomcat included with Jira Server is affected by CVE-2020-1935, CVE-2020-1938, CVE-2019-17569
-
- Closed
-
- resolves
-
JRASERVER-70127 Starting Jira 8 as a service on Windows with AdoptOpenJDK 11.0.4_11 causes an exception
-
- Closed
-
dunterwurzacher all versions are affected, as the latest Tomcat we ship with Jira is 8.5.42