#VU34157 Input validation error in Jira Software - CVE-2019-20899
Published: July 13, 2020 / Updated: August 8, 2020
Jira Software
Atlassian
Description
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
The Gadget API in Atlassian Jira Server and Data Center in affected versions allows remote attackers to make Jira unresponsive via repeated requests to a certain endpoint in the Gadget API. The affected versions are before version 8.5.4, and from version 8.6.0 before 8.6.1.