Lucene search

K
atlassianSecurity-metrics-botCWD-5466
HistorySep 26, 2019 - 4:06 p.m.

Improper Authorization in Crowd through ATST Plugin - CVE-2019-15005

2019-09-2616:06:02
security-metrics-bot
jira.atlassian.com
8

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

4.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

0.001 Low

EPSS

Percentile

22.7%

The Atlassian Troubleshooting and Support Tools (ATST) plugin prior to version 1.17.2 which was used in Crowd & Crowd Data Center before version 3.6.0, allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message may contain configuration information about the application that the plugin is installed into.

Affected configurations

Vulners
Node
atlassiancrowdRange3.2.0
OR
atlassiancrowdRange3.2.1
OR
atlassiancrowdRange3.2.2
OR
atlassiancrowdRange3.2.3
OR
atlassiancrowdRange3.3.0
OR
atlassiancrowdRange3.2.4
OR
atlassiancrowdRange3.2.5
OR
atlassiancrowdRange3.3.1
OR
atlassiancrowdRange3.4.0
OR
atlassiancrowdRange3.3.2
OR
atlassiancrowdRange3.2.6
OR
atlassiancrowdRange3.2.7
OR
atlassiancrowdRange3.3.3
OR
atlassiancrowdRange3.2.8
OR
atlassiancrowdRange3.3.4
OR
atlassiancrowdRange3.3.6
OR
atlassiancrowdRange3.3.5
OR
atlassiancrowdRange3.4.1
OR
atlassiancrowdRange3.5.0
OR
atlassiancrowdRange3.4.3
OR
atlassiancrowdRange3.4.4
OR
atlassiancrowdRange3.4.5
OR
atlassiancrowdRange3.3.7
OR
atlassiancrowdRange3.4.6
OR
atlassiancrowdRange3.4.7
OR
atlassiancrowdRange3.5.1
OR
atlassiancrowdRange3.5.2
OR
atlassiancrowdRange<3.6.0

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

4.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

0.001 Low

EPSS

Percentile

22.7%