CVE-2019-20403: Atlassian Jira Data Center

Medium severity, CVSS 5.3. EPSS: 1.5% chance of exploitation in the next 30 days.

The API in Atlassian Jira Server and Data Center before version 8.6.0 allows remote attackers to determine if a Jira project key exists or not via an information disclosure vulnerability.

Affected products

  • Atlassian Jira Data Center: from 7.13.0, before 8.5.5 (fixed in 8.5.5)
  • Atlassian Jira Server: after 7.13.0, before 8.5.5 (fixed in 8.5.5)

Published 2020-02-06. Last modified 2026-06-17.