- 
    Bug 
- 
    Resolution: Fixed
- 
    Medium 
- 
    8.5.8, 8.11.0, 8.12.0
- 
        8.05
- 
        14
- 
        Severity 2 - Major
- 
        59
- 
        
Issue Summary
The recently disclosed vulnerability regarding Apache Tomcat
affects the following versions:
    Apache Tomcat 8.x from 8.5.1 to 8.5.56
    Apache Tomcat 9.x from 9.0.0.M5 to 9.0.36
    Apache Tomcat 10.x from 10.0.0-M1 to 10.0.0-M6
Additionally, the following disclosed vulnerability regarding Tomcat:
affects the following versions:
    Apache Tomcat 7.x from 7.0.27 to 7.0.104
    Apache Tomcat 8.x from 8.5.1 to 8.5.56
    Apache Tomcat 9.x from 9.0.0.M5 to 9.0.36
    Apache Tomcat 10.x from 10.0.0-M1 to 10.0.0-M6
We should bundle a more recent version of Tomcat so that Jira is not affected by this in the future.
Steps to Reproduce
- Check the CVE reports:
Expected Results
- Not applicable.
Actual Results
- Not applicable.
Workaround
- Manually upgrade Tomcat according to our documentation.
- incorporates
- 
                    CONFSERVER-60004 Upgrade Tomcat to version 9.0.37 -         
- Closed
 
-         
- is related to
- 
                    JRASERVER-71221 Upgrade Apache Tomcat 8.5.50 - version affected by CVE-2020-9484 -         
- Closed
 
-         
- relates to
- 
                    JRASERVER-72609 Upgrade the bundled version of Apache Tomcat to 8.5.68 or later -         
- Closed
 
-         
- blocks
- 
                    PS-62845 Loading... 
- mentioned in
- 
                    Page Loading...