-
Bug
-
Resolution: Fixed
-
Low
-
6.3.4, 6.4.2, 6.5.1, 6.1.7, 5.16.9, 6.0.9, 6.2.5, 6.5.2
-
Severity 2 - Major
-
The Atlassian Troubleshooting and Support Tools (ATST) plugin prior to version 1.17.2 which was used in Bitbucket Server & Bitbucket Data Center before version 6.6.0, allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message may contain configuration information about the application that the plugin is installed into.
- is related to
-
BAM-20647 Improper Authorization in Bambooo through ATST Plugin - CVE-2019-15005
- Closed
-
CONFSERVER-58924 Improper Authorization in Confluence Server through ATST Plugin - CVE-2019-15005
- Closed
-
CWD-5466 Improper Authorization in Crowd through ATST Plugin - CVE-2019-15005
- Closed
-
FE-7226 Improper Authorization in Fisheye & Crucible through ATST Plugin - CVE-2019-15005
- Closed
-
JSWSERVER-20255 Improper Authorization in Jira Server through ATST Plugin - CVE-2019-15005
- Closed