
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2019-20901 is an open redirect vulnerability affecting Atlassian Jira's login.jsp resource. The vulnerability was discovered in versions before 8.5.2 and from version 8.6.0 before version 8.6.1. The issue was disclosed on July 13, 2020, allowing remote attackers to redirect users to different websites through the os_destination parameter (NVD, Jira Issue).
The vulnerability has been assigned a CVSS v3.x base score of 6.1 (Medium) with the vector string CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N. The vulnerability specifically affects the login.jsp resource and can be exploited through manipulation of the os_destination parameter (Rapid7).
If exploited, this vulnerability could allow attackers to redirect users to malicious websites, potentially facilitating phishing attacks. The impact primarily affects the confidentiality and integrity of the system, with no direct impact on availability (Jira Issue).
The vulnerability requires user interaction and can be exploited remotely by attackers. No known exploits have been reported in the wild at the time of disclosure (Rapid7).
Atlassian has released patches to address this vulnerability. Users are advised to upgrade to Jira version 8.5.2 if running a version before 8.5.2, or to version 8.6.1 if running version 8.6.0 (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."