CVE-2019-20897: Malicious File Upload
The avatar upload feature in affected versions of Atlassian Jira Server and Data Center allows remote attackers to achieve Denial of Service via a crafted PNG file. The affected versions are before version 8.5.4, from version 8.6.0 before 8.6.2, and from version 8.7.0 before 8.7.1.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-20897?
CVE-2019-20897 is a vulnerability in Atlassian Jira Server and Data Center that allows remote attackers to achieve Denial of Service via a crafted PNG file.
Which versions of Atlassian Jira Server and Data Center are affected?
The affected versions are before version 8.5.4, from version 8.6.0 before 8.6.2, and from version 8.7.0 before 8.7.1.
How can remote attackers exploit CVE-2019-20897?
Remote attackers can exploit CVE-2019-20897 by uploading a crafted PNG file using the avatar upload feature in the affected versions of Atlassian Jira Server and Data Center.
What is the severity of CVE-2019-20897?
CVE-2019-20897 has a severity rating of 6.5 (medium).
Is there a fix available for CVE-2019-20897?
Yes, the fix is available in versions 8.5.4, 8.6.2, and 8.7.1 of Atlassian Jira Server and Data Center.