CVE-2019-14995: Medium severity atlassian server vulnerability
Published Sep 11, 2019
·Updated
The /rest/api/1.0/render resource in Jira before version 8.4.0 allows remote anonymous attackers to determine if an attachment with a specific name exists and if an issue key is valid via a missing permissions check.
Affected Software
1 affected component
Atlassian Jira Server>=7.6.0<8.4.0
Event History
Sep 11, 2019
CVE Published
via MITRE·01:56 PM
Data Sourced
via MITRE·01:56 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-14995?
CVE-2019-14995 is classified as a medium severity vulnerability.
2
How do I fix CVE-2019-14995?
To fix CVE-2019-14995, upgrade Jira to version 8.4.0 or later.
3
Who is affected by CVE-2019-14995?
CVE-2019-14995 affects Atlassian Jira Server versions prior to 8.4.0.
4
What type of attack can CVE-2019-14995 facilitate?
CVE-2019-14995 can allow remote anonymous attackers to check for the existence of specific attachments.
5
Is CVE-2019-14995 related to permission checks in Jira?
Yes, CVE-2019-14995 involves a missing permissions check that allows unauthorized access to certain information.