CVE-2019-20101: Atlassian Data Center

Medium severity, CVSS 5.3. EPSS: 1.4% chance of exploitation in the next 30 days.

Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view whitelist rules via a Broken Access Control vulnerability in the /rest/whitelist/<version>/check endpoint. The affected versions are before version 8.13.3, and from version 8.14.0 before 8.14.1.

Affected products

  • Atlassian Data Center: before 8.13.3 (fixed in 8.13.3); version 8 only
  • Atlassian Jira: before 8.13.3 (fixed in 8.13.3); version 8 only

Published 2021-09-14. Last modified 2026-06-17.