CVE-2019-20898
Summary
| CVE | CVE-2019-20898 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-07-13 01:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to access sensitive information without being authenticated in the Global permissions screen. The affected versions are before version 8.8.0. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Atlassian | Jira | All | All | All | All |
| Application | Atlassian | Jira | All | All | All | All |
| Application | Atlassian | Jira Software Data Center | All | All | All | All |
| Application | Atlassian | Jira Software Data Center | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [JRASERVER-70942] Information disclosure in System Administration - Global Permissions - CVE-2019-20898 - Create and track feature requests for Atlassian products. | MISC | jira.atlassian.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.