-
Type:
Bug
-
Resolution: Done
-
Priority:
Medium
-
Affects Version/s: 9.11.0
-
Component/s: Security
-
9.11
-
2
-
Severity 3 - Minor
-
2
Problem
Apache Tomcat should be upgraded to 9.0.80 or a later version to fix CVE-2023-41080
Environment
- Jira v9.11
Steps to Reproduce
- Current bundled Tomcat version is Tomcat 9.0.75 which is vulnerable to CVE-2023-41080. Upgrade Tomcat to version v9.0.80 to fix this vulnerability.
Workaround
At your own risk, you can manually upgrade Tomcat as instructed on this KB:
WARNING: Unless still reproducible on official releases, Atlassian Support may refuse support requests for Jira running over unofficial Tomcat versions.