Medium severity4.9NVD Advisory· Published Feb 6, 2020· Updated Jun 17, 2026
CVE-2019-20402
CVE-2019-20402
Description
Support zip files in Atlassian Jira Server and Data Center before version 8.6.0 could be downloaded by a System Administrator user without requiring the user to re-enter their password via an improper authorization vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- cpe:2.3:a:atlassian:jira_software_data_center:*:*:*:*:*:*:*:*Range: <8.6.0
- Range: <8.6.0
- Range: unspecified
Patches
Vulnerability mechanics
References
1- jira.atlassian.com/browse/JRASERVER-70564nvdIssue TrackingVendor Advisory
News mentions
0No linked articles in our index yet.