We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2019-20106



Assigneratlassian
Reserved2019-12-30
Published2020-02-06
Updated2024-09-17

Description

Comment properties in Atlassian Jira Server and Data Center before version 7.13.12, from 8.0.0 before version 8.5.4, and 8.6.0 before version 8.6.1 allows remote attackers to make comments on a ticket to which they do not have commenting permissions via a broken access control bug.

Product status

Any version before 7.13.12
affected

8.4.1 before unspecified
affected

Any version before 8.5.4
affected

8.6.0 before unspecified
affected

Any version before 8.6.1
affected

References

https://jira.atlassian.com/browse/JRASERVER-70543

cve.org CVE-2019-20106

nvd.nist.gov CVE-2019-20106

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2019-20106
Support options

Helpdesk Telegram

Subscribe to our newsletter to learn more about our work.