JAMF sent out an email here with the following information:
Apache Tomcat recently announced a security fix for a high-severity vulnerability in their product. Because Jamf Pro requires Apache Tomcat and security is of utmost importance, we are passing on the following information so that you can take steps to mitigate the vulnerability in your environment.
JAMF sent out an email here with the following information:
According to the Apache patch notes, this vulnerability was patched in 8.5.51
Simply updating the base image to match that. Verified working just fine in prod cluster here with no other changes in functionality.