4
CVSSv2

CVE-2019-15005

Published: 08/11/2019 Updated: 14/11/2019
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message may contain configuration information about the application that the plugin is installed into. A vulnerable version of the plugin is included with Bitbucket Server / Data Center prior to 6.6.0, Confluence Server / Data Center prior to 7.0.1, Jira Server / Data Center prior to 8.3.2, Crowd / Crowd Data Center prior to 3.6.0, Fisheye prior to 4.7.2, Crucible prior to 4.7.2, and Bamboo prior to 6.10.2.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

atlassian troubleshooting and support

atlassian bamboo

atlassian bitbucket

atlassian confluence

atlassian crowd

atlassian crucible

atlassian fisheye

atlassian jira