CVE-2019-20400: High severity Atlassian Jira Server vulnerability
Published Feb 6, 2020
·Updated
The usage of Tomcat in Jira before version 8.5.2 allows local attackers with permission to write a dll file to a directory in the global path environmental variable can inject code into via a DLL hijacking vulnerability.
Affected Software
2 affected components
Atlassian Jira Server>=8.3.2<8.5.2
Atlassian Jira Server>=8.5.3<8.6.0
Event History
Feb 6, 2020
CVE Published
via MITRE·03:10 AM
Data Sourced
via MITRE·03:10 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-20400?
CVE-2019-20400 is considered a critical vulnerability due to its potential for DLL hijacking and local code injection.
2
How do I fix CVE-2019-20400?
To fix CVE-2019-20400, upgrade to Jira version 8.5.2 or later.
3
Who is affected by CVE-2019-20400?
CVE-2019-20400 affects users of Jira Server versions 8.3.2 to 8.5.1 and 8.5.3 to 8.6.0.
4
What type of attack does CVE-2019-20400 enable?
CVE-2019-20400 enables local attackers to exploit DLL hijacking to inject malicious code.
5
Can CVE-2019-20400 be exploited remotely?
No, CVE-2019-20400 requires local access to exploit the DLL hijacking vulnerability.