VulnerabilityModified
CVE-2019-20418
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to prevent users from accessing the instance via an Application Denial of Service vulnerability in the /rendering/wiki endpoint.
MEDIUM 6.5EPSS 1.02%
Does this matter?
Lower severity and a low EPSS score (1.02%). Track it; it rarely justifies an emergency change on its own.
Description
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to prevent users from accessing the instance via an Application Denial of Service vulnerability in the /rendering/wiki endpoint. The affected versions are before version 8.8.0.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 1.02% probability · 62th percentile
- CISA KEV
- Not listed
- Affected
- atlassian/jira · atlassian/jira software data center
- Source
- security@atlassian.com
References
- https://jira.atlassian.com/browse/JRASERVER-70943Issue Tracking, Vendor Advisory
- https://jira.atlassian.com/browse/JRASERVER-70943Issue Tracking, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.