Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Apache Tomcat vulnerability CVE-2021-33037

jy September 9, 2021

Environment: On-prem

Jira version: 8.19

Apache tomcat version is 8.5.65

Used Bin installer to install

 

How to upgrade the installer to 8.5.65 to 8.5.68?

Can I just download a 8.5.70 and copy the libraries over to the existing installation?

 

 

1 answer

0 votes
Daniel Eads
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
September 9, 2021

Hi @jy ,

I must first mention that Atlassian only supports the configuration we bundle - each version of Jira is tested with the version of Tomcat it ships with in the installer/archive file. If you contact Atlassian Support for assistance through support.atlassian.com, we may be unable to support your instance if it's using a non-bundled Tomcat.

That said, if you must upgrade Tomcat to mitigate the CVE, the How to upgrade Apache Tomcat version used by Jira article provides instructions.

Our development teams regularly bundle new Tomcat versions with Jira, so if possible, it would be better to sit tight and upgrade Jira itself. We are tracking the Tomcat upgrade needed for this CVE in JRASERVER-72609 on our public Jira instance. Watching that issue will let you know when a version of Jira is released that contains the patched version of Tomcat.

Cheers,
Daniel | Atlassian Support

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
SERVER
VERSION
8.19
TAGS
AUG Leaders

Atlassian Community Events