First published: Wed Jul 01 2020(Updated: )
The email client in Jira Server and Data Center before version 7.13.16, from 8.5.0 before 8.5.7, from 8.8.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to access outgoing emails between a Jira instance and the SMTP server via man-in-the-middle (MITM) vulnerability.
Credit: security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian JIRA | <7.13.14 | |
Atlassian Jira Data Center | >=8.5.0<8.5.5 | |
Atlassian Jira Data Center | >=8.8.0<8.8.2 | |
Atlassian Jira Data Center | >=8.9.0<8.9.1 | |
Atlassian Jira Server | >=8.5.0<8.5.5 | |
Atlassian Jira Server | >=8.8.0<8.8.2 | |
Atlassian Jira Server | >=8.9.0<8.9.1 | |
Atlassian Jira Software Data Center | <7.13.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-14168 is a vulnerability in the email client of Jira Server and Data Center.
CVE-2020-14168 allows remote attackers to access outgoing emails between a Jira instance and the SMTP server via a man-in-the-middle (MITM) vulnerability.
CVE-2020-14168 affects Jira Server and Data Center versions before 7.13.16, 8.5.0 to 8.5.7, 8.8.0 to 8.8.2, and 8.9.0 to 8.9.1.
CVE-2020-14168 has a severity rating of 5.9 (medium).
Yes, upgrading Jira Server and Data Center to version 7.13.16, 8.5.7, 8.8.2, or 8.9.1 will fix CVE-2020-14168.