-
Bug
-
Resolution: Fixed
-
Medium (View bug fix roadmap)
-
7.2.15, 8.0.0, 7.13.1, 7.6.11
-
7.02
-
Severity 1 - Critical
-
The issue searching component in Jira before version 8.1.0 allows remote attackers to
deny access to Jira service via denial of service vulnerability in issue search when ordering by "Epic Name".
- mentioned in
-
Page Failed to load
[JSWSERVER-20111] Denial of service in issue searching through Epic Name ordering - CVE-2019-11583
Fixed in Enterprise Release/s | New: [Download 7.13|https://confluence.atlassian.com/enterprise/atlassian-enterprise-releases-948227420.html] |
Labels | Original: CVE-2019-11583 advisory advisory-released cvss-medium denial-of-service pse-request security | New: CVE-2019-11583 advisory advisory-released application-dos cvss-medium denial-of-service pse-request security |
Fix Version/s | New: 7.13.4 [ 86493 ] |
Remote Link | New: This issue links to "Page (Confluence)" [ 442441 ] |
Description | Original: obfuscated description | New: obfuscated description |
Description | Original: obfuscated description | New: obfuscated description |
@SecurityB, looking for clarity on the vulnerable versions.
Is it just 7.13.4 or 7.13.4 or greater?