SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-5095

An issue summary information disclosure vulnerability exists in Atlassian Jira Tempo plugin, version 4.10.0.

MEDIUM 4.3EPSS 1.12%

Does this matter?

Lower severity and a low EPSS score (1.12%). Track it; it rarely justifies an emergency change on its own.

Description

An issue summary information disclosure vulnerability exists in Atlassian Jira Tempo plugin, version 4.10.0. Authenticated users can obtain the summary for issues they do not have permission to view via the Tempo plugin.

CVSS 3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS
1.12% probability · 64th percentile
CISA KEV
Not listed
Weakness
CWE-862
Affected
tempo/tempo
Source
talos-cna@cisco.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.