« Volver al listado

CVE-2019-15011

Estado: ModificadaMedia (4.3)—

The ListEntityLinksServlet resource in Application Links before version 5.0.12, from version 5.1.0 before version 5.2.11, from version 5.3.0 before version 5.3.7, from version 5.4.0 before 5.4.13, and from version 6.0.0 before 6.0.5 disclosed application link information to non-admin users via a missing permissions check.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-15011",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@atlassian.com",
      "affectedData": [
        {
          "vendor": "Atlassian",
          "product": "Application Links",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "5.0.12",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "5.1.0",
              "lessThan": "unspecified",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "5.2.11",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "5.3.0",
              "lessThan": "unspecified",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "5.3.7",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "5.4.0",
              "lessThan": "unspecified",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "5.4.13",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "6.0.0",
              "lessThan": "unspecified",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "6.0.5",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-12-17T04:15:11.257",
  "references": [
    {
      "url": "https://ecosystem.atlassian.net/browse/APL-1386",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@atlassian.com"
    },
    {
      "url": "https://ecosystem.atlassian.net/browse/APL-1386",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-276"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The ListEntityLinksServlet resource in Application Links before version 5.0.12, from version 5.1.0 before version 5.2.11, from version 5.3.0 before version 5.3.7, from version 5.4.0 before 5.4.13, and from version 6.0.0 before 6.0.5 disclosed application link information to non-admin users via a missing permissions check."
    },
    {
      "lang": "es",
      "value": "El recurso ListEntityLinksServlet en Application Links en versiones anteriores a la 5.0.12, de la versión 5.1.0 en versiones anteriores a la 5.2.11, de la versión 5.3.0 en versiones anteriores a la 5.3.7, de la versión 5.4.0 en versiones anteriores a la 5.4.13 y de la versión 6.0.0 en versiones anteriores a la 6.0.5 divulgó la información del enlace de la aplicación a usuarios no administradores a mediante una verificación de permisos faltantes."
    }
  ],
  "lastModified": "2026-06-17T02:19:30.207",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:atlassian:application_links:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "525BCC1A-F1BD-4DA4-9D71-F796699C5C70",
              "versionEndExcluding": "5.0.12"
            },
            {
              "criteria": "cpe:2.3:a:atlassian:application_links:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FDC745BF-811E-4176-99BD-DC215A540D8A",
              "versionEndExcluding": "5.2.11",
              "versionStartIncluding": "5.1.0"
            },
            {
              "criteria": "cpe:2.3:a:atlassian:application_links:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DB16B01F-FE38-4F7F-A438-522E734E1798",
              "versionEndExcluding": "5.3.7",
              "versionStartIncluding": "5.3.0"
            },
            {
              "criteria": "cpe:2.3:a:atlassian:application_links:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BB7BA4C7-CDF5-4EC3-BA7A-4DDDB220DD72",
              "versionEndExcluding": "5.4.13",
              "versionStartIncluding": "5.4.0"
            },
            {
              "criteria": "cpe:2.3:a:atlassian:application_links:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CFFFAEBE-9D34-4B1F-94AC-FBD319DE245A",
              "versionEndExcluding": "6.0.5",
              "versionStartIncluding": "6.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@atlassian.com"
}