First published: Mon Mar 23 2020(Updated: )
The Gadget API in Atlassian Jira Server and Data Center in affected versions allows remote attackers to make Jira unresponsive via repeated requests to a certain endpoint in the Gadget API. The affected versions are before version 8.5.4, and from version 8.6.0 before 8.6.1.
Credit: security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian JIRA | <8.5.4 | |
Atlassian Jira Data Center | >=8.5.5<8.6.1 | |
Atlassian Jira Data Center | >=8.6.2<8.7.0 | |
Atlassian Jira Server | >=8.5.5<8.6.1 | |
Atlassian Jira Server | >=8.6.2<8.7.0 | |
Atlassian Jira Software Data Center | <8.5.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-20899 is a vulnerability in Atlassian Jira Server and Data Center that allows remote attackers to make Jira unresponsive through repeated requests to a specific endpoint in the Gadget API.
CVE-2019-20899 has a severity rating of 5.3, which is considered medium.
The affected versions are before version 8.5.4, and from version 8.6.0 before 8.6.1 for both Atlassian Jira Server and Data Center.
Attackers can exploit CVE-2019-20899 by sending repeated requests to a certain endpoint in the Gadget API, causing Jira to become unresponsive.
Yes, the fix for CVE-2019-20899 is included in version 8.5.4 and version 8.6.1 of Atlassian Jira Server and Data Center.