Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-20099

19
FAUCET Score

CVE-2019-20099 is a Cross-Site Request Forgery (CSRF) vulnerability affecting Atlassian Jira Server and Data Center versions prior to 8.7.0. This flaw allows an attacker to trick an administrative user into making malicious HTTP requests, enabling the enumeration of hosts and open ports on the internal network where Jira is deployed. Rated as Medium severity (CVSS 4.3), its attack vector is network-based with low complexity, requiring user interaction but resulting in low confidentiality impact and no integrity or availability impact. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 7.6.15, < 8.5.4CPE matchmatch criteria
cpe:2.3:a:atlassian:jira_data_center:*:*:*:*:*:*:*:*
>= 8.5.5, < 8.6.2CPE matchmatch criteria
cpe:2.3:a:atlassian:jira_data_center:*:*:*:*:*:*:*:*
>= 7.6.15, < 8.5.4CPE matchmatch criteria
cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:*
>= 8.5.5, < 8.6.2CPE matchmatch criteria
cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:*
< 8.7.0CPE match
cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.74%
Probability of exploitation in next 30 days
EPSS Percentile
50.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0074 is in the 57th percentile among its peer group of 26,234 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (6)

boschvendor investigatingvia llm_extracted
maxkbvendor investigatingvia llm_extracted
nxpvendor investigatingvia llm_extracted
openfirevendor investigatingvia llm_extracted
openstackvendor investigatingvia llm_extracted
opnsensevendor investigatingvia llm_extracted

Vendor Advisories (6)

maxkbllm-maxkb-004195757f6772cbMEDIUM

Atlassian Jira Multiple CSRF

Feb 3, 2020
openstackllm-openstack-9d81253557a3d578MEDIUM

Atlassian Jira Multiple CSRF

Feb 3, 2020
nxpllm-nxp-34973678749f4606MEDIUM

Atlassian Jira Multiple CSRF

Feb 3, 2020
boschllm-bosch-b5afb3e2ae2f6872MEDIUM

Atlassian Jira Multiple CSRF

Feb 3, 2020
opnsensellm-opnsense-d5bf4c21516ef7afMEDIUM

Atlassian Jira Multiple CSRF

Feb 3, 2020
openfirellm-openfire-186b4744b59a181bMEDIUM

Atlassian Jira Multiple CSRF

Feb 3, 2020

References

jira.atlassian.com / browse/JRASERVER-70606
Issue TrackingVendor Advisory
tenable.com / security/research/tra-2020-05
ExploitThird Party Advisory