CVE-2019-20106
CVE-2019-20106
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 1.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
06 Feb 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Comment properties in Atlassian Jira Server and Data Center before version 7.13.12, from 8.0.0 before version 8.5.4, and 8.6.0 before version 8.6.1 allows remote attackers to make comments on a ticket to which they do not have commenting permissions via a broken access control bug.
Affected products
Atlassian · Jira Server and Data CenterWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →