CVE-2019-20409
—CVSS 3.1
9.8 critical
EPSS
2%p84
Published
()
Modified
Description
The way in which velocity templates were used in Atlassian Jira Server and Data Center prior to version 8.8.0 allowed remote attackers to gain remote code execution if they were able to exploit a server side template injection vulnerability.
- Vendors
- atlassian
- Products
- jira, jira software data center
- Weakness
- CWE-74
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.