Lucene search

K
cveMitreCVE-2015-8481
HistoryJan 08, 2016 - 7:59 p.m.

CVE-2015-8481

2016-01-0819:59:13
CWE-200
mitre
web.nvd.nist.gov
28
cve-2015-8481
atlassian
jira software
jira core
jira service desk
information disclosure
remote code execution
security vulnerability

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:N/A:N

CVSS3

3.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

4

Confidence

High

EPSS

0.001

Percentile

46.2%

Atlassian JIRA Software 7.0.3, JIRA Core 7.0.3, and the bundled JIRA Service Desk 3.0.3 installer attaches the wrong image to e-mail notifications when a user views an issue with inline wiki markup referencing an image attachment, which might allow remote attackers to obtain sensitive information by updating a different issue that includes wiki markup for an external image reference.

Affected configurations

Nvd
Node
atlassianjira_coreMatch7.0.3
Node
atlassianjira_serverMatch7.0.3
Node
atlassianjira_service_deskMatch3.0.3
VendorProductVersionCPE
atlassianjira_core7.0.3cpe:2.3:a:atlassian:jira_core:7.0.3:*:*:*:*:*:*:*
atlassianjira_server7.0.3cpe:2.3:a:atlassian:jira_server:7.0.3:*:*:*:*:*:*:*
atlassianjira_service_desk3.0.3cpe:2.3:a:atlassian:jira_service_desk:3.0.3:*:*:*:*:*:*:*

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:N/A:N

CVSS3

3.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

4

Confidence

High

EPSS

0.001

Percentile

46.2%

Related for CVE-2015-8481