CVE-2019-20404: Atlassian Jira Data Center

Medium severity, CVSS 4.3. EPSS: 1.3% chance of exploitation in the next 30 days.

The API in Atlassian Jira Server and Data Center before version 8.6.0 allows authenticated remote attackers to determine project titles they do not have access to via an improper authorization vulnerability.

Affected products

  • Atlassian Jira Data Center: from 8.2.4, before 8.6.0 (fixed in 8.6.0); from 8.6.1, before 8.7.0 (fixed in 8.7.0)
  • Atlassian Jira Server: from 8.2.4, before 8.6.0 (fixed in 8.6.0); from 8.6.1, before 8.7.0 (fixed in 8.7.0)

Published 2020-02-06. Last modified 2026-06-17.