CVE-2019-20419: Atlassian Jira Data Center

High severity, CVSS 7.8. EPSS: 0.8% chance of exploitation in the next 30 days.

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to execute arbitrary code via a DLL hijacking vulnerability in Tomcat. The affected versions are before version 8.5.5, and from version 8.6.0 before 8.7.2.

Affected products

  • Atlassian Jira Data Center: before 8.5.5 (fixed in 8.5.5); from 8.6.0, before 8.7.2 (fixed in 8.7.2)
  • Atlassian Jira Server: before 8.5.5 (fixed in 8.5.5); from 8.6.0, before 8.7.2 (fixed in 8.7.2)

Published 2020-07-03. Last modified 2026-06-17.