← Back

CVE-2019-15011

nvd nist
Published: Dec 17, 2019Modified: Nov 21, 2024

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD

Description

The ListEntityLinksServlet resource in Application Links before version 5.0.12, from version 5.1.0 before version 5.2.11, from version 5.3.0 before version 5.3.7, from version 5.4.0 before 5.4.13, and from version 6.0.0 before 6.0.5 disclosed application link information to non-admin users via a missing permissions check.

Affected (5)

1 product
Application Links
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Atlassian
Before 5.0.12
From 5.1.0 to 5.2.11
From 5.3.0 to 5.3.7
From 5.4.0 to 5.4.13
From 6.0.0 to 6.0.5

References (2)

Source: security@atlassian.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.