CVE-2019-14994
Summary
| CVE | CVE-2019-14994 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-09-19 15:15:00 UTC |
| Updated | 2019-11-14 19:19:00 UTC |
| Description | The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before version 3.9.16, from version 3.10.0 before version 3.16.8, from version 4.0.0 before version 4.1.3, from version 4.2.0 before version 4.2.5, from version 4.3.0 before version 4.3.4, and version 4.4.0 allows remote attackers with portal access to view arbitrary issues in Jira Service Desk projects via a path traversal vulnerability. Note that when the 'Anyone can email the service desk or raise a request in the portal' setting is enabled, an attacker can grant themselves portal access, allowing them to exploit the vulnerability. |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Atlassian | Jira Service Desk | All | All | All | All |
| Application | Atlassian | Jira Service Desk | All | All | All | All |
| Application | Atlassian | Jira Service Desk | 4.4.0 | All | All | All |
| Application | Atlassian | Jira Service Desk | 4.4.0 | All | All | All |
| Application | Atlassian | Jira Service Desk | All | All | All | All |
| Application | Atlassian | Jira Service Desk | All | All | All | All |
| Application | Atlassian | Jira Service Desk | 4.4.0 | All | All | All |
| Application | Atlassian | Jira Service Desk | 4.4.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Jira Service Desk Server And Data Center Path Traversal ≈ Packet Storm | MISC | packetstormsecurity.com | Third Party Advisory, VDB Entry |
| [JSDSERVER-6517] URL Path Traversal in Jira Service Desk Server and Jira Service Desk Data Center Allows Information Disclosure - CVE-2019-14994 - Create and track feature requests for Atlassian products. | MISC | jira.atlassian.com | Issue Tracking, Vendor Advisory |
| Page not found – Sam Curry | MISC | samcurry.net | Broken Link |
| Bugtraq: Jira Service Desk Server and Jira Service Desk Data Center - URL path traversal allows information disclosure - CVE-2019-14994 | BUGTRAQ | seclists.org | Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.