Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-71221

Upgrade Apache Tomcat 8.5.50 - version affected by CVE-2020-9484

      Issue Summary

      The recently disclosed vulnerability regarding Tomcat affects the following versions:

      Apache Tomcat 7x <7.0.103
      Apache Tomcat 8x <8.5.54
      Apache Tomcat 9x <9.0.34
      Apache Tomcat 10x < 10.0.0-M4

      We should bundle a more recent version of Tomcat, so that Jira is not affected by this in the future.

      Steps to Reproduce

      Expected Results

      • Not applicable.

      Actual Results

      • Not applicable.

      Workaround

            [JRASERVER-71221] Upgrade Apache Tomcat 8.5.50 - version affected by CVE-2020-9484

            Matt Doar added a comment -

            Looks like it made it into 8.5.9 on 2020-10-11

            Matt Doar added a comment - Looks like it made it into 8.5.9 on 2020-10-11
            set-jac-bot made changes -
            Fixed in Long Term Support Release/s New: [Download 8.5|https://confluence.atlassian.com/enterprise/atlassian-enterprise-releases-948227420.html]
            David Black made changes -
            Link New: This issue relates to JRASERVER-71321 [ JRASERVER-71321 ]
            David Black made changes -
            Fix Version/s New: 8.5.9 [ 92910 ]
            David Black made changes -
            Fix Version/s New: 8.12.0 [ 92098 ]
            David Black made changes -
            Labels Original: cvss-high security vulnerable-components New: advisory advisory-released cvss-high security vulnerable-components

            MadhanTest added a comment -

            Any plans to address this in Jira 8.5.x LTS ?

            MadhanTest added a comment - Any plans to address this in Jira 8.5.x LTS ?

            Any update of when it will be in Jira 8.5.x LTS ?

            mark_milgram added a comment - Any update of when it will be in Jira 8.5.x LTS ?

            Hi,

            Will this be back ported to the long term support release Jira 8.5.x?

            Thanks,

            Chris

            chris anderson added a comment - Hi, Will this be back ported to the long term support release Jira 8.5.x? Thanks, Chris
            Ignat (Inactive) made changes -
            Resolution New: Fixed [ 1 ]
            Status Original: Waiting for Release [ 12075 ] New: Closed [ 6 ]

              Unassigned Unassigned
              gperes@atlassian.com Gregory Peres (Inactive)
              Affected customers:
              1 This affects my team
              Watchers:
              9 Start watching this issue

                Created:
                Updated:
                Resolved: