The AccessLogFilter class in Jira before version 8.4.0 allows remote anonymous attackers to learn details about other users, including their username, via an information expose through caching vulnerability when Jira is configured with a reverse Proxy and or a load balancer with caching or a CDN.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: atlassian

Published: 2019-09-11T13:56:26.203376Z

Updated: 2024-09-16T18:44:06.559Z

Reserved: 2019-08-13T00:00:00

Link: CVE-2019-14997

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-09-11T14:15:11.447

Modified: 2022-03-25T17:20:54.297

Link: CVE-2019-14997

cve-icon Redhat

No data.