PT-2020-10434 · Atlassian · Jira

Published

2020-07-02

·

Updated

2022-11-21

·

CVE-2019-20417

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Atlassian Jira Server and Data Center versions prior to 8.4.2
Description The issue allows remote attackers to enumerate internal services via an Information Disclosure vulnerability. This is only exploitable if WebSudo is disabled in Jira.
Recommendations For versions prior to 8.4.2, update to version 8.4.2 or later to resolve the issue. As a temporary workaround, consider enabling WebSudo in Jira to prevent exploitation.

Related Identifiers

CVE-2019-20417

Affected Products

Jira