CVE-2019-14997
Last modified
CVE-2019-14997 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. The AccessLogFilter class in Jira before version 8.4.0 allows remote anonymous attackers to learn details about other users, including their username, via an information expose through caching vulnerability when Jira is configured with a reverse Proxy and or a load balancer with caching or a CDN.. EPSS estimates a 1.17% chance of exploitation in the next 30 days.
Description
The AccessLogFilter class in Jira before version 8.4.0 allows remote anonymous attackers to learn details about other users, including their username, via an information expose through caching vulnerability when Jira is configured with a reverse Proxy and or a load balancer with caching or a CDN.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Atlassian | Jira Server | >= 7.13.0, < 8.4.0 |
References
- https://jira.atlassian.com/browse/JRASERVER-69794Issue Tracking, Vendor Advisory
- https://jira.atlassian.com/browse/JRASERVER-69794Issue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-14997?
How severe is CVE-2019-14997?
How do I fix CVE-2019-14997?
Are you affected by CVE-2019-14997?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
