CVE-2019-14997 Information
Feb 14, 2021
cve
Description
The AccessLogFilter class in Jira before version 8.4.0 allows remote anonymous attackers to learn details about other users including their username via an information expose through caching vulnerability when Jira is configured with a reverse Proxy and or a load balancer with caching or a CDN.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Reference
https://jira.atlassian.com/browse/JRASERVER-69794
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
4.3
Share on: