First published: Tue Feb 04 2020(Updated: )
The usage of Tomcat in Jira before version 8.5.2 allows local attackers with permission to write a dll file to a directory in the global path environmental variable can inject code into via a DLL hijacking vulnerability.
Credit: security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Server | >=8.3.2<8.5.2 | |
Atlassian Server | >=8.5.3<8.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-20400 is considered a critical vulnerability due to its potential for DLL hijacking and local code injection.
To fix CVE-2019-20400, upgrade to Jira version 8.5.2 or later.
CVE-2019-20400 affects users of Jira Server versions 8.3.2 to 8.5.1 and 8.5.3 to 8.6.0.
CVE-2019-20400 enables local attackers to exploit DLL hijacking to inject malicious code.
No, CVE-2019-20400 requires local access to exploit the DLL hijacking vulnerability.