https://nvd.nist.gov/vuln/detail/CVE-2021-42340 says the tomcat version bundled with Confluence Server 7.4.13 (Tomcat/9.0.45) is vulnerable. Is Atlassian addressing this?
Confluence 7.4.16 is shipped with Tomcat 9.0.58 which should have the fix to this bug.
https://confluence.atlassian.com/doc/bundled-tomcat-and-java-versions-1005786018.html
Regards
Thiago Masutti
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.