VulnerabilityModified
CVE-2019-20899
The Gadget API in Atlassian Jira Server and Data Center in affected versions allows remote attackers to make Jira unresponsive via repeated requests to a certain endpoint in the Gadget API.
MEDIUM 5.3EPSS 2.14%
Does this matter?
Lower severity and a low EPSS score (2.14%). Track it; it rarely justifies an emergency change on its own.
Description
The Gadget API in Atlassian Jira Server and Data Center in affected versions allows remote attackers to make Jira unresponsive via repeated requests to a certain endpoint in the Gadget API. The affected versions are before version 8.5.4, and from version 8.6.0 before 8.6.1.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- EPSS
- 2.14% probability · 81th percentile
- CISA KEV
- Not listed
- Affected
- atlassian/jira · atlassian/jira data center · atlassian/jira server · atlassian/jira software data center
- Source
- security@atlassian.com
References
- https://jira.atlassian.com/browse/JRASERVER-70808Vendor Advisory
- https://jira.atlassian.com/browse/JRASERVER-70808Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.