ZeroHour

CVE-2019-20899

CVSS 3.1
5.3 medium
EPSS
2%p81
Published
()
Modified
Description

The Gadget API in Atlassian Jira Server and Data Center in affected versions allows remote attackers to make Jira unresponsive via repeated requests to a certain endpoint in the Gadget API. The affected versions are before version 8.5.4, and from version 8.6.0 before 8.6.1.

Vendors
atlassian
Products
jira, jira data center, jira server, jira software data center
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

In the news

No ingested article mentions this CVE yet.