cbcvebase.
CVE-2019-20402
published 2020-02-06

CVE-2019-20402: Support zip files in Atlassian Jira Server and Data Center before version 8.6.0 could be downloaded by a System Administrator user without requiring the user…

medium4.9CVSS 3.1
AVNACLPRHUINSUCNIHAN
Support zip files in Atlassian Jira Server and Data Center before version 8.6.0 could be downloaded by a System Administrator user without requiring the user to re-enter their password via an improper authorization vulnerability.

Affected

3 ranges
VendorProductVersion rangeFixed in
atlassianjira< 8.6.08.6.0
atlassianjira_server>= unspecified < 8.6.08.6.0
atlassianjira_software_data_center< 8.6.08.6.0