Vulnerability Description
The JMX monitoring flag in Atlassian Jira Server and Data Center before version 8.6.0 allows remote attackers to turn the JMX monitoring flag off or on via a Cross-site request forgery (CSRF) vulnerability.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Atlassian | Jira Data Center | >= 7.13.0, < 8.6.0 |
| Atlassian | Jira Server | >= 7.13.0, < 8.6.0 |
Related Weaknesses (CWE)
References
- https://jira.atlassian.com/browse/JRASERVER-70570Issue TrackingVendor Advisory
- https://jira.atlassian.com/browse/JRASERVER-70570Issue TrackingVendor Advisory
FAQ
What is CVE-2019-20405?
CVE-2019-20405 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The JMX monitoring flag in Atlassian Jira Server and Data Center before version 8.6.0 allows remote attackers to turn the JMX monitoring flag off or on via a Cross-site request forgery (CSRF) vulnerab...
How severe is CVE-2019-20405?
CVE-2019-20405 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-20405?
Check the references section above for vendor advisories and patch information. Affected products include: Atlassian Jira Data Center, Atlassian Jira Server.