Unrated severityNVD Advisory· Published Sep 11, 2019· Updated Sep 16, 2024
CVE-2019-14995
CVE-2019-14995
Description
The /rest/api/1.0/render resource in Jira before version 8.4.0 allows remote anonymous attackers to determine if an attachment with a specific name exists and if an issue key is valid via a missing permissions check.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- jira.atlassian.com/browse/JRASERVER-69792mitrex_refsource_CONFIRM
- www.talosintelligence.com/vulnerability_reports/TALOS-2019-0836mitrex_refsource_MISC
- www.talosintelligence.com/vulnerability_reports/TALOS-2019-0837mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.