#VU21153 Missing authorization in Jira Software - CVE-2019-14955 

 

#VU21153 Missing authorization in Jira Software - CVE-2019-14955

Published: September 17, 2019


Vulnerability identifier: #VU21153
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/U:Green
CVE-ID: CVE-2019-14955
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Jira Software
Software vendor:
Atlassian

Description

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to missing permissions check in the "/rest/api/1.0/render" API endpoint. A remote attacker can differentiate between valid attachment names and invalid attachment names for any given issue.



Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links