PT-2019-13930 · Atlassian · Jira+8

Julian Frey

+1

·

Published

2019-11-08

·

Updated

2019-11-14

·

CVE-2019-15005

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Atlassian Troubleshooting and Support Tools plugin versions prior to 1.17.2 Bitbucket Server / Data Center versions prior to 6.6.0 Confluence Server / Data Center versions prior to 7.0.1 Jira Server / Data Center versions prior to 8.3.2 Crowd / Crowd Data Center versions prior to 3.6.0 Fisheye versions prior to 4.7.2 Crucible versions prior to 4.7.2 Bamboo versions prior to 6.10.2
Description The issue allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message may contain configuration information about the application that the plugin is installed into.
Recommendations Update the Atlassian Troubleshooting and Support Tools plugin to version 1.17.2 or later. Update Bitbucket Server / Data Center to version 6.6.0 or later. Update Confluence Server / Data Center to version 7.0.1 or later. Update Jira Server / Data Center to version 8.3.2 or later. Update Crowd / Crowd Data Center to version 3.6.0 or later. Update Fisheye to version 4.7.2 or later. Update Crucible to version 4.7.2 or later. Update Bamboo to version 6.10.2 or later.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-15005

Affected Products

Troubleshooting/Support Tools
Bamboo
Bitbucket
Bitbucket Server
Confluence
Crowd
Crucible
Fisheye
Jira