CVE-2019-20898

HIGH

Atlassian Jira <8.8.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to access sensitive information without being authenticated in the Global permissions screen. The affected versions are before version 8.8.0.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_misc
https://jira.atlassian.com/browse/JRASERVER-70942

Scores

CVSS v3 7.5
EPSS 0.0029
EPSS Percentile 52.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

Status published
Products (2)
atlassian/jira < 8.8.0
atlassian/jira_software_data_center < 8.8.0
Published Jul 13, 2020
Tracked Since Feb 18, 2026