CVE-2019-20405: CSRF
Published Feb 6, 2020
·Updated
The JMX monitoring flag in Atlassian Jira Server and Data Center before version 8.6.0 allows remote attackers to turn the JMX monitoring flag off or on via a Cross-site request forgery (CSRF) vulnerability.
Affected Software
2 affected components
Atlassian Jira Data Center>=7.13.0<8.6.0
Atlassian Jira Server>=7.13.0<8.6.0
Event History
Feb 6, 2020
CVE Published
via MITRE·03:10 AM
Data Sourced
via MITRE·03:10 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-20405?
CVE-2019-20405 is considered a medium severity vulnerability due to its potential for CSRF exploitation.
2
How do I fix CVE-2019-20405?
To fix CVE-2019-20405, upgrade to Atlassian Jira Server and Data Center version 8.6.0 or higher.
3
What types of software are affected by CVE-2019-20405?
CVE-2019-20405 affects Atlassian Jira Server and Data Center versions between 7.13.0 and 8.6.0.
4
Can CVE-2019-20405 be exploited remotely?
Yes, CVE-2019-20405 can be exploited remotely by attackers through a CSRF attack.
5
What does CVE-2019-20405 allow an attacker to do?
CVE-2019-20405 allows attackers to toggle the JMX monitoring flag on or off, potentially compromising system performance.