Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-70813

DoS in avatar upload via crafted PNG file - CVE-2019-20897

      The avatar upload feature in affected versions of Atlassian Jira Server and Data Center allows remote attackers to achieve Denial of Service via a crafted PNG file.

      Affected versions

      • version < 8.5.4
      • 8.6.0 ≤ version ≤ 8.7.0
      • 8.7.0 ≤ version < 8.7.1

      Fixed versions

      • 8.5.4
      • 8.7.1
      • 8.8.0

       

            [JRASERVER-70813] DoS in avatar upload via crafted PNG file - CVE-2019-20897

            David Black made changes -
            Labels Original: CVE-2019-20897 advisory advisory-to-release application-dos bounty cvss-medium denial-of-service monsters security New: CVE-2019-20897 advisory advisory-released application-dos bounty cvss-medium denial-of-service monsters security
            Dave (Inactive) made changes -
            Fix Version/s Original: 8.6.2 [ 91193 ]
            Dave (Inactive) made changes -
            Description Original: The avatar upload feature in affected versions of Atlassian Jira Server and Data Center allows remote attackers to achieve Denial of Service via a crafted PNG file.

            *Affected versions*
             * version < 8.5.4
             * 8.6.0 ≤ version < 8.6.2
             * 8.7.0 ≤ version < 8.7.1

            *Fixed versions*
             * 8.5.4
             * 8.6.2
             * 8.7.1
             * 8.8.0

             
            New: The avatar upload feature in affected versions of Atlassian Jira Server and Data Center allows remote attackers to achieve Denial of Service via a crafted PNG file.

            *Affected versions*
             * version < 8.5.4
             * 8.6.0 ≤ version ≤ 8.7.0
             * 8.7.0 ≤ version < 8.7.1

            *Fixed versions*
             * 8.5.4
             * 8.7.1
             * 8.8.0

             
            AB made changes -
            Summary Original: DoS in avatar upload via crafted PNG file New: DoS in avatar upload via crafted PNG file - CVE-2019-20897
            AB made changes -
            Labels Original: advisory advisory-to-release application-dos bounty cve-in-progress cvss-medium denial-of-service monsters security New: CVE-2019-20897 advisory advisory-to-release application-dos bounty cvss-medium denial-of-service monsters security
            AB made changes -
            Labels Original: advisory advisory-to-release application-dos bounty cvss-medium denial-of-service monsters security New: advisory advisory-to-release application-dos bounty cve-in-progress cvss-medium denial-of-service monsters security
            David Black made changes -
            Labels Original: advisory advisory-released advisory-to-release application-dos bounty cvss-medium denial-of-service monsters security New: advisory advisory-to-release application-dos bounty cvss-medium denial-of-service monsters security
            David Black made changes -
            Labels Original: advisory advisory-released application-dos bounty cvss-medium denial-of-service monsters security New: advisory advisory-released advisory-to-release application-dos bounty cvss-medium denial-of-service monsters security
            David Black made changes -
            Labels Original: advisory advisory-to-release application-dos bounty cvss-medium denial-of-service monsters security New: advisory advisory-released application-dos bounty cvss-medium denial-of-service monsters security
            set-jac-bot made changes -

              Unassigned Unassigned
              security-metrics-bot Security Metrics Bot
              Affected customers:
              0 This affects my team
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: