CVE-2019-20409: Critical severity atlassian jira vulnerability
The way in which velocity templates were used in Atlassian Jira Server and Data Center prior to version 8.8.0 allowed remote attackers to gain remote code execution if they were able to exploit a server side template injection vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-20409?
CVE-2019-20409 is a vulnerability in Atlassian Jira Server and Data Center versions prior to 8.8.0 that allows remote attackers to gain remote code execution through server side template injection.
How severe is CVE-2019-20409?
CVE-2019-20409 has a severity score of 9.8, which is classified as critical.
How does CVE-2019-20409 affect Atlassian Jira Server and Data Center?
CVE-2019-20409 affects Atlassian Jira Server and Data Center versions prior to 8.8.0.
What is the Common Weakness Enumeration (CWE) ID for CVE-2019-20409?
CVE-2019-20409 is associated with CWE-74, which is a code injection vulnerability.
Is there a patch available for CVE-2019-20409?
Yes, the vulnerability has been fixed in version 8.8.0 of Atlassian Jira Server and Data Center.