Vulnerability Description
The usage of Tomcat in Jira before version 8.5.2 allows local attackers with permission to write a dll file to a directory in the global path environmental variable can inject code into via a DLL hijacking vulnerability.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Atlassian | Jira Server | >= 8.3.2, < 8.5.2 |
Related Weaknesses (CWE)
References
- https://jira.atlassian.com/browse/JRASERVER-70407Vendor Advisory
- https://jira.atlassian.com/browse/JRASERVER-70407Vendor Advisory
FAQ
What is CVE-2019-20400?
CVE-2019-20400 is a vulnerability with a CVSS score of 7.8 (HIGH). The usage of Tomcat in Jira before version 8.5.2 allows local attackers with permission to write a dll file to a directory in the global path environmental variable can inject code into via a DLL hija...
How severe is CVE-2019-20400?
CVE-2019-20400 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-20400?
Check the references section above for vendor advisories and patch information. Affected products include: Atlassian Jira Server.