CVE-2019-20100

MEDIUM

Atlassian Jira Server and Data Center - Cross-Site Request Forgery in Application Links Plugin

Title source: llm
STIX 2.1

Description

The Atlassian Application Links plugin is vulnerable to cross-site request forgery (CSRF). The following versions are affected: all versions prior to 5.4.21, from version 6.0.0 before version 6.0.12, from version 6.1.0 before version 6.1.2, from version 7.0.0 before version 7.0.2, and from version 7.1.0 before version 7.1.3. The vulnerable plugin is used by Atlassian Jira Server and Data Center before version 8.7.0. An attacker could exploit this by tricking an administrative user into making malicious HTTP requests, allowing the attacker to enumerate hosts and open ports on the internal network where Jira server is present.

References (3)

Core 3
Core References
Exploit, Third Party Advisory x_refsource_misc
https://www.tenable.com/security/research/tra-2020-06
Vendor Advisory x_refsource_misc
https://ecosystem.atlassian.net/browse/APL-1390
Issue Tracking, Vendor Advisory x_refsource_misc
https://jira.atlassian.com/browse/JRASERVER-70607

Scores

CVSS v3 4.7
EPSS 0.0030
EPSS Percentile 53.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N

Details

CWE
CWE-352
Status published
Products (3)
atlassian/jira 7.0.0 - 8.4.5
atlassian/jira_data_center 7.0.0 - 8.5.4
atlassian/jira_server 8.5.5 - 8.6.2
Published Feb 12, 2020
Tracked Since Feb 18, 2026