Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Is Confluence Server going to be patched for CVE-2021-42340

Peter Krismer
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
March 23, 2022

https://nvd.nist.gov/vuln/detail/CVE-2021-42340 says the tomcat version bundled with Confluence Server 7.4.13 (Tomcat/9.0.45) is vulnerable. Is Atlassian addressing this?

1 answer

0 votes
Thiago Masutti
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
April 1, 2022

Hi @Peter Krismer 

Confluence 7.4.16 is shipped with Tomcat 9.0.58 which should have the fix to this bug.

https://confluence.atlassian.com/doc/bundled-tomcat-and-java-versions-1005786018.html

Regards

Thiago Masutti

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events