CVE-2019-3399: High severity Atlassian Jira vulnerability
Published Apr 30, 2019
·Updated
The BrowseProjects.jspa resource in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remote attackers to see information for archived projects through a missing authorisation check.
Affected Software
2 affected components
Atlassian Jira<7.13.2
Atlassian Jira Server>=8.0.0<8.0.2
Event History
Apr 30, 2019
CVE Published
via MITRE·03:28 PM
Data Sourced
via MITRE·03:28 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-3399?
CVE-2019-3399 is classified as a medium severity vulnerability.
2
How do I fix CVE-2019-3399?
To mitigate CVE-2019-3399, upgrade Jira to version 7.13.2 or version 8.0.2 or later.
3
What does CVE-2019-3399 expose?
CVE-2019-3399 allows remote attackers to see information for archived projects due to a missing authorization check.
4
Which versions of Jira are affected by CVE-2019-3399?
Versions of Jira before 7.13.2 and from 8.0.0 before 8.0.2 are affected by CVE-2019-3399.
5
Is CVE-2019-3399 related to Jira Server?
Yes, CVE-2019-3399 also affects Jira Server versions in the specified ranges.