VulnerabilityModified
CVE-2019-11583
The issue searching component in Jira before version 8.1.0 allows remote attackers to deny access to Jira service via denial of service vulnerability in issue search when ordering by "Epic Name".
MEDIUM 6.5EPSS 1.50%
Does this matter?
Lower severity and a low EPSS score (1.50%). Track it; it rarely justifies an emergency change on its own.
Description
The issue searching component in Jira before version 8.1.0 allows remote attackers to deny access to Jira service via denial of service vulnerability in issue search when ordering by "Epic Name".
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 1.50% probability · 73th percentile
- CISA KEV
- Not listed
- Affected
- atlassian/jira
- Source
- security@atlassian.com
References
- http://www.securityfocus.com/bid/108901Third Party Advisory
- https://jira.atlassian.com/browse/JSWSERVER-20111Issue Tracking, Vendor Advisory
- http://www.securityfocus.com/bid/108901Third Party Advisory
- https://jira.atlassian.com/browse/JSWSERVER-20111Issue Tracking, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.