Security Advisory
CVE-2019-16906
7.5
HIGH
Vulnerability Description
An issue was discovered in the Infosysta "In-App & Desktop Notifications" app 1.6.13_J8 for Jira. By using plugins/servlet/nfj/PushNotification?username= with a modified username, a different user's notifications can be read without authentication/authorization. These notifications are then no longer displayed to the normal user.
Published Date
October 31, 2019
Official Source
NIST NVD Advisory