First published: Thu Feb 06 2020(Updated: )
Support zip files in Atlassian Jira Server and Data Center before version 8.6.0 could be downloaded by a System Administrator user without requiring the user to re-enter their password via an improper authorization vulnerability.
Credit: security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian JIRA | <8.6.0 | |
Atlassian Jira Software Data Center | <8.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-20402 is a vulnerability in Atlassian Jira Server and Data Center before version 8.6.0 that allows a System Administrator user to download support zip files without requiring password re-entry.
CVE-2019-20402 has a severity rating of 4.9, which is considered medium.
To fix CVE-2019-20402, upgrade Atlassian Jira Server and Data Center to version 8.6.0 or later.
You can find more information about CVE-2019-20402 on the Atlassian Jira bug tracker: https://jira.atlassian.com/browse/JRASERVER-70564