CVE-2019-20401: Atlassian Jira Server
Medium severity, CVSS 6.5. EPSS: 0.8% chance of exploitation in the next 30 days.
Various installation setup resources in Jira before version 8.5.2 allow remote attackers to configure a Jira instance, which has not yet finished being installed, via Cross-site request forgery (CSRF) vulnerabilities.
Affected products
- Atlassian Jira Server: from 7.6.15, before 8.5.2 (fixed in 8.5.2); from 8.5.3, before 8.6.0 (fixed in 8.6.0)
Published 2020-02-06. Last modified 2026-06-17.