CVE-2019-14995: Atlassian Jira Server
Medium severity, CVSS 5.3. EPSS: 3% chance of exploitation in the next 30 days.
The /rest/api/1.0/render resource in Jira before version 8.4.0 allows remote anonymous attackers to determine if an attachment with a specific name exists and if an issue key is valid via a missing permissions check.
Affected products
- Atlassian Jira Server: from 7.6.0, before 8.4.0 (fixed in 8.4.0)
Published 2019-09-11. Last modified 2026-06-17.