The version of Apache Tomcat included with Jira Server is affected by CVE-2020-1935, CVE-2020-1938, CVE-2019-17569

XMLWordPrintable

    • 8.05
    • 19
    • Severity 2 - Major
    • 48

      Issue Summary

      The recently disclosed vulnerabilities regarding Apache Tomcat

      Which affects the following versions:

      Apache Tomcat 8.x from 8.5.0 before 8.5.51

      We should bundle a more recent version of Tomcat so that Jira is not affected by this in the future.

      Steps to Reproduce

      • Not applicable.

      Expected Results

      • Not applicable.

      Actual Results

      • Not applicable.

      Workaround

              Assignee:
              Pawel Przytarski
              Reporter:
              Solomon Cherian
              Votes:
              0 Vote for this issue
              Watchers:
              15 Start watching this issue

                Created:
                Updated:
                Resolved: