Hi
I'm using atlassian/jira-software:8.20 and it uses tomcat 8.5.65. This version of tomcat has classification references CVE-2021-30640, CVE-2021-33037, CVE-2021-42340 and should update Apache Tomcat to the latest version. Is there coming new version of atlassian/jira-software with updated tomcat? or is it possible to upgrade tomcat only in docker image?
Adding to what Pramodh has said, never upgrade the tomcat like that, usually jira bundles with specific version of tomcat and upgrading that would result in breaking of the installation of application.
so you are on Jira 8.20 and next latest version is 8.21 from supported platform of 8.21 also you wont get updated tomcat check this link https://confluence.atlassian.com/adminjiraserver/supported-platforms-938846830.html
So we have to wait for the next application release or a explicit patch for the CVE that atlassian releases.
Regards,
Vishwas
Welcome to the community 🙂
You need to upgrade the application, there's no tomcat upgrade in Jira or any of the other Atlassian applications
Now for Jira, here's the latest version of release notes
https://confluence.atlassian.com/jirasoftware/jira-software-8-21-x-release-notes-1095249705.html
Thanks,
Pramodh
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.