---
cve: "CVE-2019-14995"
severity: "LOW"
cvss: 3.1
epss: "3%"
vendor: "Atlassian"
kev: false
exploited: false
published: "2019-09-11 13:56:26"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-19T10:28:02+02:00"
---

# CVE-2019-14995

> 3.1 LOW

## Beschreibung

The /rest/api/1.0/render resource in Jira before version 8.4.0 allows remote anonymous attackers to determine if an attachment with a specific name exists and if an issue key is valid via a missing permissions check.

## Referenzen

- <https://jira.atlassian.com/browse/JRASERVER-69792>
- <https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0836>
- <https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0837>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2019-14995) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
