CVE-2019-20409: Atlassian Jira
Critical severity, CVSS 9.8. EPSS: 2.5% chance of exploitation in the next 30 days.
The way in which velocity templates were used in Atlassian Jira Server and Data Center prior to version 8.8.0 allowed remote attackers to gain remote code execution if they were able to exploit a server side template injection vulnerability.
Affected products
- Atlassian Jira: before 8.8.0 (fixed in 8.8.0)
- Atlassian Jira Software Data Center: before 8.8.0 (fixed in 8.8.0)
Published 2020-06-23. Last modified 2026-06-17.