Vulnerabilities > Atlassian > Jira Data Center > 8.6.1

DATE CVE VULNERABILITY TITLE RISK
2020-02-12 CVE-2019-20098 Cross-Site Request Forgery (CSRF) vulnerability in Atlassian Jira Server
The VerifySmtpServerConnection!add.jspa component in Atlassian Jira Server and Data Center before version 8.7.0 is vulnerable to cross-site request forgery (CSRF).
network
atlassian CWE-352
4.3
2020-02-06 CVE-2019-20404 Unspecified vulnerability in Atlassian Jira Data Center and Jira Server
The API in Atlassian Jira Server and Data Center before version 8.6.0 allows authenticated remote attackers to determine project titles they do not have access to via an improper authorization vulnerability.
network
low complexity
atlassian
4.0