First published: Fri Jul 03 2020(Updated: )
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to execute arbitrary code via a DLL hijacking vulnerability in Tomcat. The affected versions are before version 8.5.5, and from version 8.6.0 before 8.7.2.
Credit: security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Data Center | <8.5.5 | |
Atlassian Data Center | >=8.6.0<8.7.2 | |
Atlassian Server | <8.5.5 | |
Atlassian Server | >=8.6.0<8.7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-20419 has a critical severity level due to the potential for remote code execution.
To mitigate CVE-2019-20419, upgrade to version 8.5.5 or later, or between 8.6.0 and 8.7.2 for Atlassian Jira Server and Data Center.
CVE-2019-20419 affects Atlassian Jira Server and Data Center versions prior to 8.5.5 and versions from 8.6.0 up to, but not including, 8.7.2.
CVE-2019-20419 is a DLL hijacking vulnerability that allows remote attackers to execute arbitrary code.
There is no documented workaround for CVE-2019-20419; upgrading to the patched versions is recommended.