CVE Database
/

CVE-2019-15005

Back to search

CVE-2019-15005

Published: Nov 8, 2019

Modified: Sep 16, 2024

PUBLISHED

Description

The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message may contain configuration information about the application that the plugin is installed into. A vulnerable version of the plugin is included with Bitbucket Server / Data Center before 6.6.0, Confluence Server / Data Center before 7.0.1, Jira Server / Data Center before 8.3.2, Crowd / Crowd Data Center before 3.6.0, Fisheye before 4.7.2, Crucible before 4.7.2, and Bamboo before 6.10.2.

VendorProductVersions

Atlassian

Bitbucket Server

affected
unspecified - < 6.6.0

Atlassian

Jira Server

affected
unspecified - < 8.3.2

Atlassian

Confluence Server

affected
unspecified - < 7.0.1

Atlassian

Crowd

affected
unspecified - < 3.6.0

Atlassian

Fisheye

affected
unspecified - < 4.7.2

Atlassian

Crucible

affected
unspecified - < 4.7.2

Atlassian

Bamboo

affected
unspecified - < 6.10.2

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now