CVE-2019-20405

MEDIUM

Atlassian Jira Server and Data Center 7.13.0-8.5.x - Cross-Site Request Forgery via JMX Monitoring Flag

Title source: llm
STIX 2.1

Description

The JMX monitoring flag in Atlassian Jira Server and Data Center before version 8.6.0 allows remote attackers to turn the JMX monitoring flag off or on via a Cross-site request forgery (CSRF) vulnerability.

References (1)

Core 1
Core References
Issue Tracking, Vendor Advisory x_refsource_misc
https://jira.atlassian.com/browse/JRASERVER-70570

Scores

CVSS v3 4.3
EPSS 0.0018
EPSS Percentile 39.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Details

CWE
CWE-352
Status published
Products (2)
atlassian/jira_data_center 7.13.0 - 8.6.0
atlassian/jira_server 7.13.0 - 8.6.0
Published Feb 06, 2020
Tracked Since Feb 18, 2026