Atlassian Update
3325Warning Date
Severity Level
Warning Number
Target Sector
7 November, 2019
● Critical
2019-598
All
Description:
Atlassian has released security update to address two vulnerabilities in following versions of Jira Service Desk Server and Jira Service Desk Data Center:
- Versions before 3.9.17
- From 3.10.0 before 3.16.11
- From 4.0.0 before 4.2.6
- From 4.3.0 before 4.3.5
- From 4.4.0 before 4.4.3
- From 4.5.0 before 4.5.1
Threats:
The vulnerabilities cause information disclosure, which could allow an attacker with portal access to view all issues within Jira Service Desk projects, Jira Core projects, and Jira Software projects.
Best practice and Recommendations:
The CERT team encourages users to review Atlassian security advisory and apply the necessary updates: https://confluence.atlassian.com/jira/jira-service-desk-security-advisory-2019-11-06-979412717.html