CVE-2019-20899: Medium severity Atlassian Jira vulnerability
The Gadget API in Atlassian Jira Server and Data Center in affected versions allows remote attackers to make Jira unresponsive via repeated requests to a certain endpoint in the Gadget API. The affected versions are before version 8.5.4, and from version 8.6.0 before 8.6.1.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-20899?
CVE-2019-20899 is a vulnerability in Atlassian Jira Server and Data Center that allows remote attackers to make Jira unresponsive through repeated requests to a specific endpoint in the Gadget API.
What is the severity rating of CVE-2019-20899?
CVE-2019-20899 has a severity rating of 5.3, which is considered medium.
Which versions of Atlassian Jira are affected by CVE-2019-20899?
The affected versions are before version 8.5.4, and from version 8.6.0 before 8.6.1 for both Atlassian Jira Server and Data Center.
How can attackers exploit CVE-2019-20899?
Attackers can exploit CVE-2019-20899 by sending repeated requests to a certain endpoint in the Gadget API, causing Jira to become unresponsive.
Is there a fix for CVE-2019-20899?
Yes, the fix for CVE-2019-20899 is included in version 8.5.4 and version 8.6.1 of Atlassian Jira Server and Data Center.