First published: Mon Jun 29 2020(Updated: )
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view sensitive information via an Information Disclosure vulnerability in the comment restriction feature. The affected versions are before version 7.6.17, from version 7.7.0 before 7.13.9, and from version 8.0.0 before 8.4.2.
Credit: security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian JIRA | <7.6.17 | |
Atlassian Jira Data Center | >=7.7.0<7.13.9 | |
Atlassian Jira Data Center | >=8.0.0<8.4.2 | |
Atlassian Jira Server | >=7.7.0<7.13.9 | |
Atlassian Jira Server | >=8.0.0<8.4.2 | |
Atlassian Jira Software Data Center | <7.6.17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-20410 is an Information Disclosure vulnerability in Atlassian Jira Server and Data Center.
Remote attackers can exploit CVE-2019-20410 to view sensitive information through the comment restriction feature.
Affected versions of Atlassian Jira Server and Data Center are before version 7.6.17, from version 7.7.0 before 7.13.9, and from version 8.0.0 before 8.4.2.
CVE-2019-20410 has a severity rating of Medium.
To fix CVE-2019-20410, you should upgrade your Atlassian Jira Server or Data Center to version 7.6.17, 7.13.9, or 8.4.2.