PT-2019-13930 · Atlassian · Jira+8
Julian Frey
+1
·
Published
2019-11-08
·
Updated
2019-11-14
·
CVE-2019-15005
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Atlassian Troubleshooting and Support Tools plugin versions prior to 1.17.2
Bitbucket Server / Data Center versions prior to 6.6.0
Confluence Server / Data Center versions prior to 7.0.1
Jira Server / Data Center versions prior to 8.3.2
Crowd / Crowd Data Center versions prior to 3.6.0
Fisheye versions prior to 4.7.2
Crucible versions prior to 4.7.2
Bamboo versions prior to 6.10.2
Description
The issue allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message may contain configuration information about the application that the plugin is installed into.
Recommendations
Update the Atlassian Troubleshooting and Support Tools plugin to version 1.17.2 or later.
Update Bitbucket Server / Data Center to version 6.6.0 or later.
Update Confluence Server / Data Center to version 7.0.1 or later.
Update Jira Server / Data Center to version 8.3.2 or later.
Update Crowd / Crowd Data Center to version 3.6.0 or later.
Update Fisheye to version 4.7.2 or later.
Update Crucible to version 4.7.2 or later.
Update Bamboo to version 6.10.2 or later.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Troubleshooting/Support Tools
Bamboo
Bitbucket
Bitbucket Server
Confluence
Crowd
Crucible
Fisheye
Jira