SB2020062322 - Multiple vulnerabilities in Atlassian JIRA
Published: June 23, 2020 Updated: August 8, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 secuirty vulnerabilities.
1) Information disclosure (CVE-ID: CVE-2019-20898)
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to access sensitive information without being authenticated in the Global permissions screen. The affected versions are before version 8.8.0.
2) Input validation error (CVE-ID: CVE-2019-20418)
The vulnerability allows remote attackers to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can prevent users from accessing the instance via an Application Denial of Service vulnerability in the /rendering/wiki endpoint.
3) Improper Neutralization of Special Elements in Output Used by a Downstream Component (CVE-ID: CVE-2019-20409)
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
The way in which velocity templates were used in Atlassian Jira Server and Data Center prior to version 8.8.0 allowed remote attackers to gain remote code execution if they were able to exploit a server side template injection vulnerability.
Remediation
Install update from vendor's website.