First published: Wed Jul 01 2020(Updated: )
The MessageBundleResource resource in Jira Server and Data Center before version 7.13.4, from 8.5.0 before 8.5.5, from 8.8.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to impact the application's availability via an Denial of Service (DoS) vulnerability.
Credit: security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian JIRA | <7.13.14 | |
Atlassian Jira Data Center | >=8.5.0<8.5.5 | |
Atlassian Jira Data Center | >=8.8.0<8.8.2 | |
Atlassian Jira Data Center | >=8.9.0<8.9.1 | |
Atlassian Jira Server | >=8.5.0<8.5.5 | |
Atlassian Jira Server | >=8.8.0<8.8.2 | |
Atlassian Jira Server | >=8.9.0<8.9.1 | |
Atlassian Jira Software Data Center | <7.13.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-14167 is a Denial of Service (DoS) vulnerability in Jira Server and Data Center before version 7.13.4, 8.5.0 before 8.5.5, 8.8.0 before 8.8.2, and 8.9.0 before 8.9.1.
CVE-2020-14167 allows remote attackers to impact the availability of Jira Server and Data Center through a Denial of Service (DoS) attack.
CVE-2020-14167 has a severity value of 7.5, which is considered high.
CVE-2020-14167 affects Jira Server and Data Center versions before 7.13.4, 8.5.0 before 8.5.5, 8.8.0 before 8.8.2, and 8.9.0 before 8.9.1.
To fix CVE-2020-14167, it is recommended to upgrade Jira Server and Data Center to version 7.13.4, 8.5.5, 8.8.2, or 8.9.1, depending on the affected version.