The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message may contain configuration information about the application that the plugin is installed into. A vulnerable version of the plugin is included with Bitbucket Server / Data Center before 6.6.0, Confluence Server / Data Center before 7.0.1, Jira Server / Data Center before 8.3.2, Crowd / Crowd Data Center before 3.6.0, Fisheye before 4.7.2, Crucible before 4.7.2, and Bamboo before 6.10.2.
2019-11-08T04:15:10.307
2024-11-21T04:27:51.487
Modified
CVSSv3.1: 4.3 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:N/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | atlassian | troubleshooting_and_support | < 1.17.2 | Yes |
Application | atlassian | bamboo | < 6.10.2 | Yes |
Application | atlassian | bitbucket | < 6.6.0 | Yes |
Application | atlassian | confluence | < 7.0.1 | Yes |
Application | atlassian | crowd | < 3.6.0 | Yes |
Application | atlassian | crucible | < 4.7.2 | Yes |
Application | atlassian | fisheye | < 4.7.2 | Yes |
Application | atlassian | jira | < 8.3.2 | Yes |