CVE-2019-20401: CSRF
Various installation setup resources in Jira before version 8.5.2 allow remote attackers to configure a Jira instance, which has not yet finished being installed, via Cross-site request forgery (CSRF) vulnerabilities.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-20401?
CVE-2019-20401 has been classified as a medium severity vulnerability.
How do I fix CVE-2019-20401?
To fix CVE-2019-20401, upgrade your Jira Server to version 8.5.2 or later if you are using a vulnerable version.
What are the potential impacts of CVE-2019-20401?
CVE-2019-20401 allows remote attackers to configure an unfinished Jira installation, potentially leading to unauthorized access or manipulation.
Which versions of Jira are affected by CVE-2019-20401?
CVE-2019-20401 affects Jira Server versions prior to 8.5.2 and versions between 8.5.3 and 8.6.0.
Is CVE-2019-20401 a remote exploit?
Yes, CVE-2019-20401 can be exploited remotely by attackers via Cross-site request forgery (CSRF) vulnerabilities.