CVE-2019-11585

MEDIUM

Jira <7.13.6, <8.0.0-<8.2.3, <8.3.0-<8.3.2 - Open Redirect

Title source: llm
STIX 2.1

Description

The startup.jsp resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open redirect.

References (1)

Core 1
Core References
Issue Tracking, Vendor Advisory x_refsource_misc
https://jira.atlassian.com/browse/JRASERVER-69784

Scores

CVSS v3 6.1
EPSS 0.0016
EPSS Percentile 36.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-601
Status published
Products (2)
atlassian/jira < 7.13.6
atlassian/jira_server 8.0.0 - 8.2.3
Published Aug 23, 2019
Tracked Since Feb 18, 2026