ZeroHour

CVE-2019-20897

CVSS 3.1
6.5 medium
EPSS
2%p78
Published
()
Modified
Description

The avatar upload feature in affected versions of Atlassian Jira Server and Data Center allows remote attackers to achieve Denial of Service via a crafted PNG file. The affected versions are before version 8.5.4, from version 8.6.0 before 8.6.2, and from version 8.7.0 before 8.7.1.

Vendors
atlassian
Products
jira, jira data center, jira server, jira software data center
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.