CVE-2019-20101

3 documents3 sources
Severity
5.3MEDIUM
EPSS
1.6%
top 18.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 14
Latest updateMay 24

Description

Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view whitelist rules via a Broken Access Control vulnerability in the /rest/whitelist//check endpoint. The affected versions are before version 8.13.3, and from version 8.14.0 before 8.14.1.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages4 packages

CVEListV5atlassian/jira_data_centerunspecified8.13.3+2
CVEListV5atlassian/jira_serverunspecified8.13.3+2
NVDatlassian/data_center< 8.13.3+1
NVDatlassian/jira< 8.13.3+1

🔴Vulnerability Details

2
GHSA
GHSA-26xp-wjvm-542h: Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view whitelist rules via a Broken Access Control vulner2022-05-24
CVEList
CVE-2019-20101: Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view whitelist rules via a Broken Access Control vulner2021-09-14
CVE-2019-20101 (MEDIUM CVSS 5.3) | Affected versions of Atlassian Jira | cvebase.io