Vulnerabilities > Atlassian > Jira > 7.13.16

DATE CVE VULNERABILITY TITLE RISK
2019-11-08 CVE-2019-15005 Missing Authorization vulnerability in Atlassian products
The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check.
network
low complexity
atlassian CWE-862
4.0
2019-09-11 CVE-2019-8449 Missing Authentication for Critical Function vulnerability in Atlassian Jira
The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate usernames via an information disclosure vulnerability.
network
low complexity
atlassian CWE-306
5.0