Analysis of CVE-2019-14994 - Jira Service Desk Path Traversal leads to Massive Information Disclosure

from blog Blog | Sam Curry, | ↗ original
The CVE-2019-14994 vulnerability allows an attacker, if able to access the customer portal, to traverse to the administrative portal and view issues within all Jira projects contained in the vulnerable instance. This could include Jira Service Desk projects, Jira Core projects, and Jira Software projects