Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-20409

Опубликовано: 23 июн. 2020
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

The way in which velocity templates were used in Atlassian Jira Server and Data Center prior to version 8.8.0 allowed remote attackers to gain remote code execution if they were able to exploit a server side template injection vulnerability.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:atlassian:jira:*:*:*:*:*:*:*:*
Версия до 8.8.0 (исключая)
cpe:2.3:a:atlassian:jira_software_data_center:*:*:*:*:*:*:*:*
Версия до 8.8.0 (исключая)

EPSS

Процентиль: 87%
0.03481
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-74

Связанные уязвимости

github
около 3 лет назад

The way in which velocity templates were used in Atlassian Jira Server and Data Center prior to version 8.8.0 allowed remote attackers to gain remote code execution if they were able to exploit a server side template injection vulnerability.

EPSS

Процентиль: 87%
0.03481
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-74