CVE-2019-15011

The ListEntityLinksServlet resource in Application Links before version 5.0.12, from version 5.1.0 before version 5.2.11, from version 5.3.0 before version 5.3.7, from version 5.4.0 before 5.4.13, and from version 6.0.0 before 6.0.5 disclosed application link information to non-admin users via a missing permissions check.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
atlassianCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 39%
VendorProductVersion
atlassianapplication_links
𝑥
< 5.0.12
atlassianapplication_links
5.1.0 ≤
𝑥
< 5.2.11
atlassianapplication_links
5.3.0 ≤
𝑥
< 5.3.7
atlassianapplication_links
5.4.0 ≤
𝑥
< 5.4.13
atlassianapplication_links
6.0.0 ≤
𝑥
< 6.0.5
𝑥
= Vulnerable software versions