CVE-2019-20106: Atlassian Jira
Medium severity, CVSS 4.3. EPSS: 1.2% chance of exploitation in the next 30 days.
Comment properties in Atlassian Jira Server and Data Center before version 7.13.12, from 8.0.0 before version 8.5.4, and 8.6.0 before version 8.6.1 allows remote attackers to make comments on a ticket to which they do not have commenting permissions via a broken access control bug.
Affected products
- Atlassian Jira: before 7.13.12 (fixed in 7.13.12)
- Atlassian Jira Data Center: from 8.0.0, before 8.5.4 (fixed in 8.5.4); version 8.6.0 only
- Atlassian Jira Server: from 8.0.0, before 8.5.4 (fixed in 8.5.4); version 8.6.0 only
- Atlassian Jira Software Data Center: before 7.13.12 (fixed in 7.13.12)
Published 2020-02-06. Last modified 2026-06-17.