Vulnerability Description
The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before version 3.9.16, from version 3.10.0 before version 3.16.8, from version 4.0.0 before version 4.1.3, from version 4.2.0 before version 4.2.5, from version 4.3.0 before version 4.3.4, and version 4.4.0 allows remote attackers with portal access to view arbitrary issues in Jira Service Desk projects via a path traversal vulnerability. Note that when the 'Anyone can email the service desk or raise a request in the portal' setting is enabled, an attacker can grant themselves portal access, allowing them to exploit the vulnerability.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Atlassian | Jira Service Desk | < 3.9.16 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/154574/Jira-Service-Desk-Server-And-Data-CeThird Party AdvisoryVDB Entry
- https://jira.atlassian.com/browse/JSDSERVER-6517Issue TrackingVendor Advisory
- https://samcurry.net/analysis-of-cve-2019-14994/Broken Link
- https://seclists.org/bugtraq/2019/Sep/39Mailing ListThird Party Advisory
- http://packetstormsecurity.com/files/154574/Jira-Service-Desk-Server-And-Data-CeThird Party AdvisoryVDB Entry
- https://jira.atlassian.com/browse/JSDSERVER-6517Issue TrackingVendor Advisory
- https://samcurry.net/analysis-of-cve-2019-14994/Broken Link
- https://seclists.org/bugtraq/2019/Sep/39Mailing ListThird Party Advisory
FAQ
What is CVE-2019-14994?
CVE-2019-14994 is a vulnerability with a CVSS score of 7.5 (HIGH). The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before version 3.9.16, from version 3.10.0 before version 3.16.8, from version 4.0.0 before version ...
How severe is CVE-2019-14994?
CVE-2019-14994 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-14994?
Check the references section above for vendor advisories and patch information. Affected products include: Atlassian Jira Service Desk.