CVE-2019-20404: Medium severity Atlassian Jira Data Center vulnerability
Published Feb 6, 2020
·Updated
The API in Atlassian Jira Server and Data Center before version 8.6.0 allows authenticated remote attackers to determine project titles they do not have access to via an improper authorization vulnerability.
Affected Software
4 affected components
Atlassian Jira Data Center>=8.2.4<8.6.0
Atlassian Jira Data Center>=8.6.1<8.7.0
Atlassian Jira Server>=8.2.4<8.6.0
Atlassian Jira Server>=8.6.1<8.7.0
Event History
Feb 6, 2020
CVE Published
via MITRE·03:10 AM
Data Sourced
via MITRE·03:10 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-20404?
CVE-2019-20404 has a medium severity rating due to its improper authorization vulnerability.
2
How do I fix CVE-2019-20404?
To fix CVE-2019-20404, update Atlassian Jira Server and Data Center to version 8.6.0 or later.
3
Who is affected by CVE-2019-20404?
CVE-2019-20404 affects users of Atlassian Jira Server and Data Center versions prior to 8.6.0.
4
What type of vulnerability is CVE-2019-20404?
CVE-2019-20404 is classified as an improper authorization vulnerability.
5
Can CVE-2019-20404 be exploited remotely?
Yes, CVE-2019-20404 can be exploited by authenticated remote attackers.