Uploaded image for project: 'Bamboo Data Center'
  1. Bamboo Data Center
  2. BAM-20647

Improper Authorization in Bambooo through ATST Plugin - CVE-2019-15005

      The Atlassian Troubleshooting and Support Tools (ATST) plugin prior to version 1.17.2 which was used in Bamboo before version 6.10.2, allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message may contain configuration information about the application that the plugin is installed into.

            [BAM-20647] Improper Authorization in Bambooo through ATST Plugin - CVE-2019-15005

            Said made changes -
            Labels Original: CVE-2019-15005 advisory advisory-released cvss-medium security New: CVE-2019-15005 advisory advisory-released cvss-medium improper-authorization security
            David Black made changes -
            Labels Original: CVE-2019-15005 advisory advisory-released advisory-to-release cvss-medium security New: CVE-2019-15005 advisory advisory-released cvss-medium security
            David Black made changes -
            Labels Original: CVE-2019-15005 advisory advisory-to-release cvss-medium security New: CVE-2019-15005 advisory advisory-released advisory-to-release cvss-medium security
            Security Original: Atlassian Staff [ 10750 ]
            David Black made changes -
            Description Original: The Atlassian Troubleshooting and Support Tools (ATST) plugin prior to version 1.17.2 in Bamboo before version 6.10.2, allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message may contain configuration information about the application that the plugin is installed into. New: The Atlassian Troubleshooting and Support Tools (ATST) plugin prior to version 1.17.2 which was used in Bamboo before version 6.10.2, allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message may contain configuration information about the application that the plugin is installed into.
            David Black made changes -
            Description Original: The Atlassian Troubleshooting and Support Tools (ATST) plugin prior to version 1.17.2 in Bamboo from 6.2.0 and before 6.10.2, allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message may contain configuration information about the application that the plugin is installed into. New: The Atlassian Troubleshooting and Support Tools (ATST) plugin prior to version 1.17.2 in Bamboo before version 6.10.2, allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message may contain configuration information about the application that the plugin is installed into.
            David Black made changes -
            Link New: This issue relates to BSERV-11960 [ BSERV-11960 ]
            David Black made changes -
            Labels Original: advisory advisory-to-release cve-2019-15003 cvss-medium security New: CVE-2019-15005 advisory advisory-to-release cvss-medium security
            David Black made changes -
            Summary Original: Improper Authorization in Bambooo through ATST Plugin - CVE-2019-15003 New: Improper Authorization in Bambooo through ATST Plugin - CVE-2019-15005
            Yasmine made changes -
            Link Original: This issue is cloned from BSERV-11960 [ BSERV-11960 ]
            Yasmine made changes -
            Description Original: ATST plugin (version prior to 1.17.2) in Atlassian Bamboo from version 6.2.0 before version 6.10.2 allows unprivileged user to create a periodic scan and access the results via email. New: The Atlassian Troubleshooting and Support Tools (ATST) plugin prior to version 1.17.2 in Bamboo from 6.2.0 and before 6.10.2, allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message may contain configuration information about the application that the plugin is installed into.

              Unassigned Unassigned
              security-metrics-bot Security Metrics Bot
              Affected customers:
              0 This affects my team
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: