CVE Vulnerabilities

CVE-2020-14167

Published: Jul 01, 2020 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The MessageBundleResource resource in Jira Server and Data Center before version 7.13.4, from 8.5.0 before 8.5.5, from 8.8.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to impact the applications availability via an Denial of Service (DoS) vulnerability.

Affected Software

NameVendorStart VersionEnd Version
JiraAtlassian*7.13.14 (excluding)
Jira_data_centerAtlassian8.5.0 (including)8.5.5 (excluding)
Jira_data_centerAtlassian8.8.0 (including)8.8.2 (excluding)
Jira_data_centerAtlassian8.9.0 (including)8.9.1 (excluding)
Jira_serverAtlassian8.5.0 (including)8.5.5 (excluding)
Jira_serverAtlassian8.8.0 (including)8.8.2 (excluding)
Jira_serverAtlassian8.9.0 (including)8.9.1 (excluding)
Jira_software_data_centerAtlassian*7.13.14 (excluding)

References