- 
    Bug 
- 
    Resolution: Fixed
- 
    Low 
- 
    8.9.0
- 
        8.09
- 
        2
- 
        Severity 2 - Major
- 
        
Issue Summary
The recently disclosed vulnerability regarding Tomcat affects the following versions:
    Apache Tomcat 7x <7.0.103
    Apache Tomcat 8x <8.5.54
    Apache Tomcat 9x <9.0.34
    Apache Tomcat 10x < 10.0.0-M4
We should bundle a more recent version of Tomcat, so that Jira is not affected by this in the future.
Steps to Reproduce
- Check the CVE report.
Expected Results
- Not applicable.
Actual Results
- Not applicable.
Workaround
- Manually upgrade Tomcat according to our documentation.
- relates to
- 
                    JRASERVER-71321 Upgrade the bundled version of Apache Tomcat to 8.5.57 -         
- Closed
 
-