CVE Feed

    Dashboard / CVE / CVE-2019-15005

    CVE-2019-15005

    The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message may contain configuration information about the application that the plugin is installed into. A vulnerable version of the plugin is included with Bitbucket Server / Data Center before 6.6.0, Confluence Server / Data Center before 7.0.1, Jira Server / Data Center before 8.3.2, Crowd / Crowd Data Center before 3.6.0, Fisheye before 4.7.2, Crucible before 4.7.2, and Bamboo before 6.10.2.

    Published:Nov 8, 2019
    Last Modified:Nov 21, 2024
    EPS:Nov 8, 2019
    EPSS Score:0.00195
    CVSS Score:4.3

    Affected Products

    Vendor
    Atlassian
    Product
    Bamboo
    Vendor
    Atlassian
    Product
    Bitbucket
    Vendor
    Atlassian
    Product
    Confluence
    Vendor
    Atlassian
    Product
    Crowd
    Vendor
    Atlassian
    Product
    Crucible
    Vendor
    Atlassian
    Product
    Fisheye
    Vendor
    Atlassian
    Product
    Jira
    Vendor
    Atlassian
    Product
    Troubleshooting And Support

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High