📦

jira_service_desk

Vendor: atlassian

Actively Exploited 0 CISA KEV List
PoC / Exploits 2 Code Available
Total RCEs 2 Remote Access
Total CVEs 15 Total Indexed
Avg. EPSS 12.33% Exploit Prob.
Latest CVE CVE-2021-43959 Jul 26

Security Vulnerability Index

Page 2 / 2
7.5 CVSS

The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before version 3.9.16, from version 3.10.0 before version 3.16.8, from version 4.0.0 before version 4.1.3, from version 4.2.0 before version 4.2.5, from version 4.3.0 before version 4.3.4, and version 4.4.0 allows remote attackers with portal access to view arbitrary issues in Jira Service Desk projects via a path traversal vulnerability. Note that when the 'Anyone can email the service desk or raise a request in the portal' setting is enabled, an attacker can grant themselves portal access, allowing them to exploit the vulnerability.

EPSS: 5.88%
3.1 CVSS

Atlassian JIRA Software 7.0.3, JIRA Core 7.0.3, and the bundled JIRA Service Desk 3.0.3 installer attaches the wrong image to e-mail notifications when a user views an issue with inline wiki markup referencing an image attachment, which might allow remote attackers to obtain sensitive information by updating a different issue that includes wiki markup for an external image reference.

EPSS: 1.26%