CVE-2019-20402: Atlassian Jira
Medium severity, CVSS 4.9. EPSS: 0.8% chance of exploitation in the next 30 days.
Support zip files in Atlassian Jira Server and Data Center before version 8.6.0 could be downloaded by a System Administrator user without requiring the user to re-enter their password via an improper authorization vulnerability.
Affected products
- Atlassian Jira: before 8.6.0 (fixed in 8.6.0)
- Atlassian Jira Software Data Center: before 8.6.0 (fixed in 8.6.0)
Published 2020-02-06. Last modified 2026-06-17.