Vulnerability Description
The MessageBundleResource resource in Jira Server and Data Center before version 7.13.4, from 8.5.0 before 8.5.5, from 8.8.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to impact the application's availability via an Denial of Service (DoS) vulnerability.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Atlassian | Jira | < 7.13.14 |
| Atlassian | Jira Data Center | >= 8.5.0, < 8.5.5 |
| Atlassian | Jira Server | >= 8.5.0, < 8.5.5 |
| Atlassian | Jira Software Data Center | < 7.13.14 |
References
- https://jira.atlassian.com/browse/JRASERVER-71197Vendor Advisory
- https://jira.atlassian.com/browse/JRASERVER-71197Vendor Advisory
FAQ
What is CVE-2020-14167?
CVE-2020-14167 is a vulnerability with a CVSS score of 7.5 (HIGH). The MessageBundleResource resource in Jira Server and Data Center before version 7.13.4, from 8.5.0 before 8.5.5, from 8.8.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to impact...
How severe is CVE-2020-14167?
CVE-2020-14167 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-14167?
Check the references section above for vendor advisories and patch information. Affected products include: Atlassian Jira, Atlassian Jira Data Center, Atlassian Jira Server, Atlassian Jira Software Data Center.