CVE-2019-15006

CWE-9133 documents3 sources
Severity
6.5MEDIUM
EPSS
7.6%
top 8.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 19
Latest updateMay 24

Description

There was a man-in-the-middle (MITM) vulnerability present in the Confluence Previews plugin in Confluence Server and Confluence Data Center. This plugin was used to facilitate communication with the Atlassian Companion application. The Confluence Previews plugin in Confluence Server and Confluence Data Center communicated with the Companion application via the atlassian-domain-for-localhost-connections-only.com domain name, the DNS A record of which points at 127.0.0.1. Additionally, a signed c

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:NExploitability: 2.2 | Impact: 4.2

Affected Packages3 packages

CVEListV5atlassian/confluence_server6.11.0unspecified+9
NVDatlassian/confluence_server6.14.06.15.10+2
NVDatlassian/confluence6.11.06.13.10

Patches

🔴Vulnerability Details

2
GHSA
GHSA-86mx-982p-mgc2: There was a man-in-the-middle (MITM) vulnerability present in the Confluence Previews plugin in Confluence Server and Confluence Data Center2022-05-24
CVEList
CVE-2019-15006: There was a man-in-the-middle (MITM) vulnerability present in the Confluence Previews plugin in Confluence Server and Confluence Data Center2019-12-19