CVE-2019-14997

The AccessLogFilter class in Jira before version 8.4.0 allows remote anonymous attackers to learn details about other users, including their username, via an information expose through caching vulnerability when Jira is configured with a reverse Proxy and or a load balancer with caching or a CDN.
References
Link Resource
https://jira.atlassian.com/browse/JRASERVER-69794 Issue Tracking Vendor Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:*

Information

Published : 2019-09-11 07:15

Updated : 2022-03-25 10:20


NVD link : CVE-2019-14997

Mitre link : CVE-2019-14997


JSON object : View

Advertisement

dedicated server usa

Products Affected

atlassian

  • jira_server