Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-71221

Upgrade Apache Tomcat 8.5.50 - version affected by CVE-2020-9484

      Issue Summary

      The recently disclosed vulnerability regarding Tomcat affects the following versions:

      Apache Tomcat 7x <7.0.103
      Apache Tomcat 8x <8.5.54
      Apache Tomcat 9x <9.0.34
      Apache Tomcat 10x < 10.0.0-M4

      We should bundle a more recent version of Tomcat, so that Jira is not affected by this in the future.

      Steps to Reproduce

      Expected Results

      • Not applicable.

      Actual Results

      • Not applicable.

      Workaround

            [JRASERVER-71221] Upgrade Apache Tomcat 8.5.50 - version affected by CVE-2020-9484

            set-jac-bot made changes -
            Fixed in Long Term Support Release/s New: [Download 8.5|https://confluence.atlassian.com/enterprise/atlassian-enterprise-releases-948227420.html]
            David Black made changes -
            Link New: This issue relates to JRASERVER-71321 [ JRASERVER-71321 ]
            David Black made changes -
            Fix Version/s New: 8.5.9 [ 92910 ]
            David Black made changes -
            Fix Version/s New: 8.12.0 [ 92098 ]
            David Black made changes -
            Labels Original: cvss-high security vulnerable-components New: advisory advisory-released cvss-high security vulnerable-components
            Ignat (Inactive) made changes -
            Resolution New: Fixed [ 1 ]
            Status Original: Waiting for Release [ 12075 ] New: Closed [ 6 ]
            Bugfix Automation Bot made changes -
            Support reference count Original: 1 New: 2
            Daniel Rauf made changes -
            Fix Version/s New: 8.11.0 [ 92097 ]
            Daniel Rauf made changes -
            Status Original: In Progress [ 3 ] New: Waiting for Release [ 12075 ]
            Daniel Rauf made changes -
            Status Original: Needs Triage [ 10030 ] New: In Progress [ 3 ]

              Unassigned Unassigned
              gperes@atlassian.com Gregory Peres (Inactive)
              Affected customers:
              1 This affects my team
              Watchers:
              9 Start watching this issue

                Created:
                Updated:
                Resolved: