First published: Thu Feb 06 2020(Updated: )
Various installation setup resources in Jira before version 8.5.2 allow remote attackers to configure a Jira instance, which has not yet finished being installed, via Cross-site request forgery (CSRF) vulnerabilities.
Credit: security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Server | >=7.6.15<8.5.2 | |
Atlassian Server | >=8.5.3<8.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-20401 has been classified as a medium severity vulnerability.
To fix CVE-2019-20401, upgrade your Jira Server to version 8.5.2 or later if you are using a vulnerable version.
CVE-2019-20401 allows remote attackers to configure an unfinished Jira installation, potentially leading to unauthorized access or manipulation.
CVE-2019-20401 affects Jira Server versions prior to 8.5.2 and versions between 8.5.3 and 8.6.0.
Yes, CVE-2019-20401 can be exploited remotely by attackers via Cross-site request forgery (CSRF) vulnerabilities.