CVE-2019-20101: Medium severity atlassian data center vulnerability
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view whitelist rules via a Broken Access Control vulnerability in the /rest/whitelist/<version>/check endpoint. The affected versions are before version 8.13.3, and from version 8.14.0 before 8.14.1.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-20101?
CVE-2019-20101 is a vulnerability in Atlassian Jira Server and Data Center that allows anonymous remote attackers to view whitelist rules.
How can the CVE-2019-20101 vulnerability be exploited?
The CVE-2019-20101 vulnerability can be exploited by sending a request to the /rest/whitelist/<version>/check endpoint.
Which versions of Atlassian Jira Server and Data Center are affected by CVE-2019-20101?
Versions before 8.13.3 of Atlassian Jira Server and Data Center, and versions from 8.14.0 before 8.14.1 are affected by CVE-2019-20101.
What is the severity of CVE-2019-20101?
CVE-2019-20101 has a severity rating of 5.3 (medium).
How can I fix the CVE-2019-20101 vulnerability?
To fix the CVE-2019-20101 vulnerability, it is recommended to upgrade to version 8.13.3 or higher of Atlassian Jira Server and Data Center.