CVE-2019-14997
The AccessLogFilter class in Jira before version 8.4.0 allows remote anonymous attackers to learn details about other users, including their username, via an information expose through caching vulnerability when Jira is configured with a reverse Proxy…
Does this matter?
Lower severity and a low EPSS score (1.17%). Track it; it rarely justifies an emergency change on its own.
Description
The AccessLogFilter class in Jira before version 8.4.0 allows remote anonymous attackers to learn details about other users, including their username, via an information expose through caching vulnerability when Jira is configured with a reverse Proxy and or a load balancer with caching or a CDN.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
- EPSS
- 1.17% probability · 66th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-524
- Affected
- atlassian/jira server
- Source
- security@atlassian.com
References
- https://jira.atlassian.com/browse/JRASERVER-69794Issue Tracking, Vendor Advisory
- https://jira.atlassian.com/browse/JRASERVER-69794Issue Tracking, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.