Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-71221

Upgrade Apache Tomcat 8.5.50 - version affected by CVE-2020-9484

    XMLWordPrintable

Details

    Description

      Issue Summary

      The recently disclosed vulnerability regarding Tomcat affects the following versions:

      Apache Tomcat 7x <7.0.103
      Apache Tomcat 8x <8.5.54
      Apache Tomcat 9x <9.0.34
      Apache Tomcat 10x < 10.0.0-M4

      We should bundle a more recent version of Tomcat, so that Jira is not affected by this in the future.

      Steps to Reproduce

      Expected Results

      • Not applicable.

      Actual Results

      • Not applicable.

      Workaround

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              gperes@atlassian.com Gregory Peres (Inactive)
              Votes:
              1 Vote for this issue
              Watchers:
              9 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: