Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-14997

Опубликовано: 11 сент. 2019
Источник: nvd
CVSS3: 4.3
CVSS2: 4.3
EPSS Низкий

Описание

The AccessLogFilter class in Jira before version 8.4.0 allows remote anonymous attackers to learn details about other users, including their username, via an information expose through caching vulnerability when Jira is configured with a reverse Proxy and or a load balancer with caching or a CDN.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:*
Версия от 7.13.0 (включая) до 8.4.0 (исключая)

EPSS

Процентиль: 42%
0.00204
Низкий

4.3 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-524
NVD-CWE-Other

Связанные уязвимости

CVSS3: 4.3
github
больше 3 лет назад

The AccessLogFilter class in Jira before version 8.4.0 allows remote anonymous attackers to learn details about other users, including their username, via an information expose through caching vulnerability when Jira is configured with a reverse Proxy and or a load balancer with caching or a CDN.

EPSS

Процентиль: 42%
0.00204
Низкий

4.3 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-524
NVD-CWE-Other