First published: Mon Jun 29 2020(Updated: )
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify Wallboard settings via a Cross-site request forgery (CSRF) vulnerability. The affected versions are before version 7.13.9, and from version 8.0.0 before 8.4.2.
Credit: security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Jira | <7.13.9 | |
Atlassian Data Center | >=7.7.0<7.13.9 | |
Atlassian Data Center | >=8.0.0<8.4.2 | |
Atlassian Server | >=8.0.0<8.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-20411 is considered a medium severity vulnerability due to its potential for exploitation through CSRF attacks.
To fix CVE-2019-20411, upgrade Atlassian Jira Server and Data Center to versions 7.13.9 or 8.4.2 and above.
CVE-2019-20411 affects Atlassian Jira Server and Data Center versions prior to 7.13.9 and versions from 8.0.0 up to but not including 8.4.2.
CVE-2019-20411 is a Cross-Site Request Forgery (CSRF) vulnerability that allows remote attackers to modify Wallboard settings.
Yes, CVE-2019-20411 can be exploited remotely by attackers to perform unauthorized actions on affected Jira instances.