CVE-2019-15011

MEDIUM

Atlassian Application Links <5.0.12, 5.1.0-5.2.11, 5.3.0-5.3.7, 5.4.0-5.4.13, 6.0.0-6.0.5 - Information Disclosure

Title source: llm
STIX 2.1

Description

The ListEntityLinksServlet resource in Application Links before version 5.0.12, from version 5.1.0 before version 5.2.11, from version 5.3.0 before version 5.3.7, from version 5.4.0 before 5.4.13, and from version 6.0.0 before 6.0.5 disclosed application link information to non-admin users via a missing permissions check.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_misc
https://ecosystem.atlassian.net/browse/APL-1386

Scores

CVSS v3 4.3
EPSS 0.0018
EPSS Percentile 39.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-276
Status published
Products (1)
atlassian/application_links < 5.0.12
Published Dec 17, 2019
Tracked Since Feb 18, 2026