CVE-2019-14997 Vulnerability Details

  /     /     /  

CVE-2019-14997 Metadata Quick Info

CVE Published: 11/09/2019 | CVE Updated: 16/09/2024 | CVE Year: 2019
Source: atlassian | Vendor: Atlassian | Product: Jira
Status : PUBLISHED

CVE-2019-14997 Description

The AccessLogFilter class in Jira before version 8.4.0 allows remote anonymous attackers to learn details about other users, including their username, via an information expose through caching vulnerability when Jira is configured with a reverse Proxy and or a load balancer with caching or a CDN.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-524
CWE Name: Information Exposure Through Caching (CWE-524)
Source: Atlassian

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).