CVE-2019-20402: Atlassian Jira

Medium severity, CVSS 4.9. EPSS: 0.8% chance of exploitation in the next 30 days.

Support zip files in Atlassian Jira Server and Data Center before version 8.6.0 could be downloaded by a System Administrator user without requiring the user to re-enter their password via an improper authorization vulnerability.

Affected products

  • Atlassian Jira: before 8.6.0 (fixed in 8.6.0)
  • Atlassian Jira Software Data Center: before 8.6.0 (fixed in 8.6.0)

Published 2020-02-06. Last modified 2026-06-17.