CVE-2019-20400: Atlassian Jira Server

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

The usage of Tomcat in Jira before version 8.5.2 allows local attackers with permission to write a dll file to a directory in the global path environmental variable can inject code into via a DLL hijacking vulnerability.

Affected products

  • Atlassian Jira Server: from 8.3.2, before 8.5.2 (fixed in 8.5.2); from 8.5.3, before 8.6.0 (fixed in 8.6.0)

Published 2020-02-06. Last modified 2026-06-17.