CVE-2019-20098 vulnerability in Atlassian Products
Published on February 12, 2020
The VerifySmtpServerConnection!add.jspa component in Atlassian Jira Server and Data Center before version 8.7.0 is vulnerable to cross-site request forgery (CSRF). An attacker could exploit this by tricking an administrative user into making malicious HTTP requests, allowing the attacker to enumerate hosts and open ports on the internal network where Jira server is present.
Products Associated with CVE-2019-20098
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2019-20098 are published in these products:
Affected Versions
Atlassian Jira Server:- Version unspecified and below 8.7.0 is affected.
Exploit Probability
EPSS
0.43%
Percentile
62.29%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.