CVE-2019-15004 vulnerability in Atlassian Products
Published on November 7, 2019
The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before 3.9.17, from 3.10.0 before 3.16.10, from 4.0.0 before 4.2.6, from 4.3.0 before 4.3.5, from 4.4.0 before 4.4.3, and from 4.5.0 before 4.5.1 allows remote attackers with portal access to view arbitrary issues in Jira Service Desk projects via a path traversal vulnerability. Note that when the 'Anyone can email the service desk or raise a request in the portal' setting is enabled, an attacker can grant themselves portal access, allowing them to exploit the vulnerability.
Products Associated with CVE-2019-15004
stack.watch emails you whenever new vulnerabilities are published in Atlassian Jira Service Desk or Atlassian Jira. Just hit a watch button to start following.
Affected Versions
Atlassian Jira Service Desk Server:- Version unspecified and below 3.9.17 is affected.
- Version 3.10.0 and below unspecified is affected.
- Version unspecified and below 3.16.10 is affected.
- Version 4.0.0 and below unspecified is affected.
- Version unspecified and below 4.2.6 is affected.
- Version 4.3.0 and below unspecified is affected.
- Version unspecified and below 4.3.5 is affected.
- Version 4.4.0 and below unspecified is affected.
- Version unspecified and below 4.4.3 is affected.
- Version 4.5.0 and below unspecified is affected.
- Version unspecified and below 4.5.1 is affected.
- Version unspecified and below 3.9.17 is affected.
- Version 3.10.0 and below unspecified is affected.
- Version unspecified and below 3.16.10 is affected.
- Version 4.0.0 and below unspecified is affected.
- Version unspecified and below 4.2.6 is affected.
- Version 4.3.0 and below unspecified is affected.
- Version unspecified and below 4.3.5 is affected.
- Version 4.4.0 and below unspecified is affected.
- Version unspecified and below 4.4.3 is affected.
- Version 4.5.0 and below unspecified is affected.
- Version unspecified and below 4.5.1 is affected.
Exploit Probability
EPSS
4.39%
Percentile
88.83%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.