
Cloud Vulnerability DB
A community-led vulnerabilities database
The vulnerability (CVE-2020-14168) affects the email client in Jira Server and Data Center across multiple versions (before version 7.13.16, from 8.5.0 before 8.5.7, from 8.8.0 before 8.8.2, and from 8.9.0 before 8.9.1). The vulnerability was discovered and reported on June 18, 2020, and was resolved on June 19, 2020 (Jira Issue).
The vulnerability is classified as a man-in-the-middle (MITM) vulnerability that affects the communication between Jira instances and SMTP servers. The CVSS 3.0 score for this vulnerability is 10 (Critical), indicating the highest severity level (Vulnerability Manager).
When exploited, this vulnerability allows remote attackers to intercept and access outgoing emails between a Jira instance and the SMTP server (CVE Mitre).
The vulnerability requires network access and can be exploited by remote attackers through a man-in-the-middle attack. No specific exploit code or active exploitation in the wild has been publicly reported (NVD).
Atlassian has released fixed versions to address this vulnerability. Users should upgrade to version 7.13.16, 8.5.7, 8.8.2, 8.9.1, or 8.10.0 depending on their current version (Jira Issue).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."