CVE-2019-14995: Atlassian Jira Server

Medium severity, CVSS 5.3. EPSS: 3% chance of exploitation in the next 30 days.

The /rest/api/1.0/render resource in Jira before version 8.4.0 allows remote anonymous attackers to determine if an attachment with a specific name exists and if an issue key is valid via a missing permissions check.

Affected products

  • Atlassian Jira Server: from 7.6.0, before 8.4.0 (fixed in 8.4.0)

Published 2019-09-11. Last modified 2026-06-17.