CVE-2019-14995

CVE-2019-14995

Vendor Atlassian
Product Jira
Weakness CWE-863 · Incorrect authorization
Published September 11, 2019
Last update September 16, 2024

CVSS base score

What the vulnerability does

01Description

The /rest/api/1.0/render resource in Jira before version 8.4.0 allows remote anonymous attackers to determine if an attachment with a specific name exists and if an issue key is valid via a missing permissions check.

Key dates

02Disclosure timeline

September 11, 2019 CVE published
September 16, 2024 Record updated