Vulnerabilities > CVE-2019-5095 - Missing Authorization vulnerability in Tempo 4.10.0

047910
CVSS 4.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
tempo
CWE-862

Summary

An issue summary information disclosure vulnerability exists in Atlassian Jira Tempo plugin, version 4.10.0. Authenticated users can obtain the summary for issues they do not have permission to view via the Tempo plugin.

Vulnerable Configurations

Part Description Count
Application
Tempo
1

Common Weakness Enumeration (CWE)

Talos

idTALOS-2019-0838
last seen2019-11-05
published2019-09-16
reporterTalos Intelligence
sourcehttp://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0838
titleAtlassian Jira Tempo plugin issue summary information disclosure vulnerability