SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-20897

The avatar upload feature in affected versions of Atlassian Jira Server and Data Center allows remote attackers to achieve Denial of Service via a crafted PNG file.

MEDIUM 6.5EPSS 1.88%

Does this matter?

Lower severity and a low EPSS score (1.88%). Track it; it rarely justifies an emergency change on its own.

Description

The avatar upload feature in affected versions of Atlassian Jira Server and Data Center allows remote attackers to achieve Denial of Service via a crafted PNG file. The affected versions are before version 8.5.4, from version 8.6.0 before 8.6.2, and from version 8.7.0 before 8.7.1.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS
1.88% probability · 78th percentile
CISA KEV
Not listed
Weakness
CWE-434
Affected
atlassian/jira · atlassian/jira data center · atlassian/jira server · atlassian/jira software data center
Source
security@atlassian.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.