CVE-2019-20106

Severity
4.3MEDIUM
EPSS
0.2%
top 56.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 6
Latest updateMay 24

Description

Comment properties in Atlassian Jira Server and Data Center before version 7.13.12, from 8.0.0 before version 8.5.4, and 8.6.0 before version 8.6.1 allows remote attackers to make comments on a ticket to which they do not have commenting permissions via a broken access control bug.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages5 packages

CVEListV5atlassian/jira_server_and_data_centerunspecified7.13.12+4
NVDatlassian/jira_data_center8.0.08.5.4+1
NVDatlassian/jira_server8.0.08.5.4+1
NVDatlassian/jira< 7.13.12

🔴Vulnerability Details

2
GHSA
GHSA-2cw7-vx4f-3wmm: Comment properties in Atlassian Jira Server and Data Center before version 72022-05-24
CVEList
CVE-2019-20106: Comment properties in Atlassian Jira Server and Data Center before version 72020-02-06
CVE-2019-20106 (MEDIUM CVSS 4.3) | Comment properties in Atlassian Jir | cvebase.io