CVE-2019-20106: Medium severity atlassian jira vulnerability
Comment properties in Atlassian Jira Server and Data Center before version 7.13.12, from 8.0.0 before version 8.5.4, and 8.6.0 before version 8.6.1 allows remote attackers to make comments on a ticket to which they do not have commenting permissions via a broken access control bug.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-20106?
CVE-2019-20106 is a vulnerability in Atlassian Jira Server and Data Center that allows remote attackers to make comments on a ticket to which they do not have commenting permissions.
What is the severity of CVE-2019-20106?
CVE-2019-20106 has a severity rating of medium with a score of 4.3.
How does CVE-2019-20106 affect Atlassian Jira Server and Data Center?
CVE-2019-20106 affects Atlassian Jira Server and Data Center versions before 7.13.12, from 8.0.0 before 8.5.4, and 8.6.0 before 8.6.1.
How can remote attackers exploit CVE-2019-20106?
Remote attackers can exploit CVE-2019-20106 by making comments on a ticket to which they do not have commenting permissions.
Is there a fix for CVE-2019-20106?
Yes, upgrading to Atlassian Jira Server and Data Center version 7.13.12, 8.5.4, or 8.6.1 (or later versions) resolves CVE-2019-20106.