CVE-2019-20400: Atlassian Jira Server
High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.
The usage of Tomcat in Jira before version 8.5.2 allows local attackers with permission to write a dll file to a directory in the global path environmental variable can inject code into via a DLL hijacking vulnerability.
Affected products
- Atlassian Jira Server: from 8.3.2, before 8.5.2 (fixed in 8.5.2); from 8.5.3, before 8.6.0 (fixed in 8.6.0)
Published 2020-02-06. Last modified 2026-06-17.