CVE-2019-15003
Summary
| CVE | CVE-2019-15003 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-11-07 04:15:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before 3.9.17, from 3.10.0 before 3.16.10, from 4.0.0 before 4.2.6, from 4.3.0 before 4.3.5, from 4.4.0 before 4.4.3, and from 4.5.0 before 4.5.1 allows remote attackers with portal access to view arbitrary issues in Jira Service Desk projects via authorization bypass. Note that when the 'Anyone can email the service desk or raise a request in the portal' setting is enabled, an attacker can grant themselves portal access, allowing them to exploit the vulnerability. |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Atlassian | Jira Service Desk | All | All | All | All |
| Application | Atlassian | Jira Service Desk | All | All | All | All |
| Application | Atlassian | Jira Service Desk | All | All | All | All |
| Application | Atlassian | Jira Service Desk | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Bugtraq: Jira Service Desk Server and Jira Service Desk Data Center Security Advisory - 2019-11-06 - CVE-2019-15003, CVE-2019-15004 | BUGTRAQ | seclists.org | Third Party Advisory |
| [JSDSERVER-6590] Authorization bypass allows information disclosure - CVE-2019-15003 - Create and track feature requests for Atlassian products. | MISC | jira.atlassian.com | Issue Tracking, Vendor Advisory |
| Jira Service Desk Server / Data Center Path Traversal ≈ Packet Storm | MISC | packetstormsecurity.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.