Security readout for executives and security teams
Plain-English summary
CVE-2019-20901 is an open redirect in Jira Server’s login page. An attacker could craft a Jira-looking login link that sends a user to another website, supporting phishing. The source bundle does not show server compromise, code execution, CVSS scoring, or confirmed active exploitation.
Executive priority
Treat this as a phishing-enablement issue, not evidence of direct server compromise. Prioritize remediation for internet-facing Jira Server and environments where Jira links are trusted by staff or customers.
Technical view
Jira Server login.jsp before 8.5.2, and 8.6.0 before 8.6.1, mishandles the os_destination parameter, allowing remote redirection to a different website. The stated impact is phishing support through open redirect abuse. No CWE, CVSS vector, proof-of-exploitation, or KEV listing is provided.
Likely exposure
Exposure is likely limited to Atlassian Jira Server instances running versions before 8.5.2, or 8.6.0 before 8.6.1, especially where the login page is reachable by users or the internet.
Exploitation context
The bundle supports remote open redirect abuse for phishing. It does not support claims of active exploitation, authentication bypass, data theft, malware delivery, or direct Jira server compromise.
Researcher notes
The public bundle is sparse: affected ranges and the vulnerable parameter are identified, but CVSS, CWE, exploit status, and detailed vendor remediation text are absent. Avoid expanding scope beyond Jira Server unless Atlassian sources confirm it.
Mitigation direction
- Upgrade affected Jira Server instances to 8.5.2, 8.6.1, or later vendor-supported versions.
- Review Atlassian JRASERVER-70408 for vendor guidance and any deployment-specific notes.
- Warn users about Jira login links that redirect to unfamiliar domains.
- Monitor login.jsp traffic for suspicious os_destination values pointing off-domain.
Validation and detection
- Inventory Jira Server versions and identify any before 8.5.2 or exactly 8.6.0.
- Confirm whether login.jsp is reachable from the internet or broad user networks.
- Review web access logs for login.jsp requests containing os_destination.
- Verify remediated systems run 8.5.2, 8.6.1, or a later supported version.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2019-20901 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://jira.atlassian.com/browse/JRASERVER-70408CVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
