I've been asked by the security team to update Jira to remediate a security issue with our on-prem install of Jira Software:
CVE-2019-12418 Apache Tomcat 8.5.0 < 8.5.49 Privilege Escalation (132413)
We are running the Long Term Support/Enterprise version 8.5.4 which runs Apache 8.5.42, and is affected by this issue.
I found this issue on the roadmap here: https://jira.atlassian.com/browse/JRASERVER-71321
and it appears that the plan is to only provide a fix in newer (non-enterprise) versions of Jira (8.12+). If I'm missing something, please let me know.
I'm trying to understand why the Long Term Support version isn't being long term supported with regard to this issue.
Any help would be appreciated