CVE-2019-15005

MEDIUM

Atlassian Troubleshooting and Support Tools < 1.17.2 - Unauthenticated Missing Authorization

Title source: llm
STIX 2.1

Description

The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message may contain configuration information about the application that the plugin is installed into. A vulnerable version of the plugin is included with Bitbucket Server / Data Center before 6.6.0, Confluence Server / Data Center before 7.0.1, Jira Server / Data Center before 8.3.2, Crowd / Crowd Data Center before 3.6.0, Fisheye before 4.7.2, Crucible before 4.7.2, and Bamboo before 6.10.2.

References (2)

Core 2
Core References
Issue Tracking, Vendor Advisory x_refsource_misc
https://jira.atlassian.com/browse/BAM-20647

Scores

CVSS v3 4.3
EPSS 0.0022
EPSS Percentile 43.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-862
Status published
Products (8)
atlassian/bamboo < 6.10.2
atlassian/bitbucket < 6.6.0
atlassian/confluence < 7.0.1
atlassian/crowd < 3.6.0
atlassian/crucible < 4.7.2
atlassian/fisheye < 4.7.2
atlassian/jira < 8.3.2
atlassian/troubleshooting_and_support < 1.17.2
Published Nov 08, 2019
Tracked Since Feb 18, 2026