The Atlassian Community Forums are currently in read-only mode. We will be relaunching on a new platform on September 22 (read more here). We apologize for the extended downtime. For concerns or questions, please email communitymanagers@atlassian.com. See you on the other side, on the new Atlassian Community Forums! :)

×

Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

CVE-2024-56337

Martin Neal
March 4, 2025

 

 

Jira v9.12.16 on Redhat 8.10

Atlassian upgrades do not address this Vulnerability\

Upgrade to Apache Tomcat version 9.0.98 or later

/opt/atlassian/jira installed version 9.0.07

 

 

 

 

 

Jira v9.12.16

1 answer

Comments for this post are closed

Community moderators have prevented the ability to post new answers.

Post a new question

1 vote
Brant Schroeder
Community Champion
March 4, 2025

@Martin Neal Atlassian does bundle their product with Apache but you should still be updating it to prevent security vulnerabilities.  If you would like to use a bundle to accomplish this you would need to move to 10.3 or higher.  If you do not want to upgrade because you are on a long-term release you can follow this help document - https://confluence.atlassian.com/jirakb/how-to-upgrade-the-apache-tomcat-version-used-by-jira-server-and-data-center-879957866.html 

As with all production upgrades you should backup your instance or even better make an image of it before performing the upgrade.  I would suggest making an image, performing the upgrade on the image and validating that everything works before making the upgrade in production.