CVE-2019-20409
Last modified
CVE-2019-20409 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The way in which velocity templates were used in Atlassian Jira Server and Data Center prior to version 8.8.0 allowed remote attackers to gain remote code execution if they were able to exploit a server side template injection vulnerability.. EPSS estimates a 2.48% chance of exploitation in the next 30 days.
Description
The way in which velocity templates were used in Atlassian Jira Server and Data Center prior to version 8.8.0 allowed remote attackers to gain remote code execution if they were able to exploit a server side template injection vulnerability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Atlassian | Jira | < 8.8.0 |
| Atlassian | Jira Software Data Center | < 8.8.0 |
References
- https://jira.atlassian.com/browse/JRASERVER-70944Issue Tracking, Vendor Advisory
- https://jira.atlassian.com/browse/JRASERVER-70944Issue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-20409?
How severe is CVE-2019-20409?
How do I fix CVE-2019-20409?
Are you affected by CVE-2019-20409?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
