https://nvd.nist.gov/vuln/detail/CVE-2021-42340 says the tomcat version bundled with Confluence Server 7.4.13 (Tomcat/9.0.45) is vulnerable. Is Atlassian addressing this?
Hi @Peter Krismer
Confluence 7.4.16 is shipped with Tomcat 9.0.58 which should have the fix to this bug.
https://confluence.atlassian.com/doc/bundled-tomcat-and-java-versions-1005786018.html
Regards
Thiago Masutti
It looks like you're new here. Sign in or register to get started.