Lucene search

K
atlassian[email protected]ATLASSIAN:JRASERVER-72310
HistoryApr 12, 2021 - 3:50 p.m.

8.5 and 8.13 LTS releases should bundle Tomcat 8.5.63 or higher

2021-04-1215:50:10
jira.atlassian.com
37

0.002 Low

EPSS

Percentile

60.0%

h3. Issue Summary
The Apache Tomcat version used by the currently available LTS (Long Term Support) releases has a few vulnerabilities, therefore the next LTS release should bundle an updated version of Tomcat.

h3. Steps to Reproduce

Not applicable.

h3. Expected Results

  • Not applicable.

h3. Actual Results

  • Not applicable.

h3. Note on fix
Tomcat version will be bumped to version [8.5.65|https://tomcat.apache.org/tomcat-8.5-doc/changelog.html]

h3. Workaround