← Back

CVE-2018-13391

nvd nist
Published: Aug 28, 2018Modified: Nov 21, 2024

JSON object

Loading...
5.3
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

The ProfileLinkUserFormat component of Jira Server before version 7.6.8, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3 and from version 7.11.0 before version 7.11.2 allows remote attackers who can access & view an issue to obtain the email address of the reporter and assignee user of an issue despite the configured email visibility setting being set to hidden.

Affected (6)

2 products
Jira
Jira Server
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Before 7.6.8
Atlassian
From 7.10.0 to 7.10.3
From 7.11.0 to 7.11.2
From 7.7.0 to 7.7.5
From 7.8.0 to 7.8.5
From 7.9.0 to 7.9.3

References (4)

Source: security@atlassian.com
Third Party AdvisoryVDB Entry
Source: security@atlassian.com
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory

Timeline

No history available yet.