None
EN
Analysis of CVE-2019-14994 - Jira Service Desk Path Traversal leads to Massive Information Disclosure
[]
Blog | Sam Curry
The CVE-2019-14994 vulnerability allows an attacker, if able to access the customer portal, to traverse to the administrative portal and view issues within all Jira projects contained in the vulnerable instance. If an attacker can authenticate to submit support tickets (if the `anyone can email the service desk or raise a request in the portal` setting is enabled) on the following versions of Jira Service Desk, then the issue is exploitable: The administrative Jira Portal being accessed via directory traversal from the Customer portal