CVE-2019-15011
Summary
| CVE | CVE-2019-15011 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-12-17 04:15:00 UTC |
| Updated | 2019-12-30 17:45:00 UTC |
| Description | The ListEntityLinksServlet resource in Application Links before version 5.0.12, from version 5.1.0 before version 5.2.11, from version 5.3.0 before version 5.3.7, from version 5.4.0 before 5.4.13, and from version 6.0.0 before 6.0.5 disclosed application link information to non-admin users via a missing permissions check. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [APL-1386] Information disclosure in the listEntityLinks servlet resource - CVE-2019-15011 - Ecosystem Jira |
MISC |
ecosystem.atlassian.net |
Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 730438 Update TITLE manually (JRASERVER-70409)
- 730440 Atlassian Jira Server Information Disclosure Vulnerability (JRASERVER-70409)