The AccessLogFilter class in Jira before version 8.4.0 allows remote anonymous attackers to learn details about other users, including their username, via an information expose through caching vulnerability when Jira is configured with a reverse Proxy and or a load balancer with caching or a CDN.
References
Link Resource
https://jira.atlassian.com/browse/JRASERVER-69794 Issue Tracking Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: atlassian

Published: 2019-09-10T00:00:00

Updated: 2019-09-11T13:56:26

Reserved: 2019-08-13T00:00:00


Link: CVE-2019-14997

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2019-09-11T14:15:11.447

Modified: 2022-03-25T17:20:54.297


Link: CVE-2019-14997

JSON object: View

cve-icon Redhat Information

No data.