-
Bug
-
Resolution: Fixed
-
Low (View bug fix roadmap)
-
7.8.4, 8.3.0
-
7.08
-
Severity 2 - Major
-
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability on the UserPickerBrowser.jspa page.
Affected versions:
- version < 7.13.9
- 8.0.0 ≤ version < 8.4.2
Fixed versions:
- 7.13.9
- 8.4.2
- 8.5.0
[JRASERVER-70883] DoS via missing input validation in UserPickerBrowser.jspa - CVE-2019-20413
Labels | Original: CVE-2019-20413 advisory advisory-to-release application-dos cvss-high denial-of-service security | New: CVE-2019-20413 advisory advisory-released application-dos cvss-high denial-of-service security |
Summary | Original: DoS via missing input validation in UserPickerBrowser.jspa | New: DoS via missing input validation in UserPickerBrowser.jspa - CVE-2019-20413 |
Labels | Original: advisory advisory-to-release application-dos cve-in-progress cvss-high denial-of-service security | New: CVE-2019-20413 advisory advisory-to-release application-dos cvss-high denial-of-service security |
Labels | Original: advisory advisory-to-release application-dos cvss-high denial-of-service security | New: advisory advisory-to-release application-dos cve-in-progress cvss-high denial-of-service security |
Fixed in Enterprise Release/s | New: [Download 7.13, 8.5|https://confluence.atlassian.com/enterprise/atlassian-enterprise-releases-948227420.html] |
Introduced in Version | New: 7.08 |
Security | Original: Atlassian Staff [ 10750 ] |
Resolution | New: Fixed [ 1 ] | |
Status | Original: Needs Triage [ 10030 ] | New: Closed [ 6 ] |
Description | Original: Component in Atlassian Jira Server and Data Center from version 7.8.4 before version 7.13.9, from version 8.3.0 before version 8.4.2 and before version 8.5.0 allows remote attackers to IMPACT via a VULN_INFO. |
New:
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability on the UserPickerBrowser.jspa page.
*Affected versions:* * version < 7.13.9 * 8.0.0 ≤ version < 8.4.2 *Fixed versions:* * 7.13.9 * 8.4.2 * 8.5.0 |
Summary | Original: Sanitised security issue 2dfc76d2f5165c370f230badcb9e0ebcbeda445e0d707860719c05d5c654130d | New: DoS via missing input validation in UserPickerBrowser.jspa |