Description
Atlassian JIRA is a tool that is used for bug tracking, issue tracking, and project management.
This instance of Atlassian JIRA is misconfigured to allow an attacker to sign up (create a new account) just by navigating to the signup page that is accessible at the URL /servicedesk/customer/user/signup. After the attacker has created a new account it's possible for him/her to access the support portal.
Remediation
Please consult the Atlassian documentation (from the References link) that explains how to choose the right settings to secure your Atlassian JIRA installation.
References
Related Vulnerabilities
WordPress Plugin Wbcom Designs-BuddyPress Group Reviews Security Bypass (2.8.3)
WordPress Plugin Passster-Password Protection Security Bypass (3.5.5.8)
WordPress Plugin WordPress Download Manager Security Bypass (2.7.2)
WordPress Plugin Livemesh SiteOrigin Widgets Security Bypass (2.5.1)
WordPress Possible Security Bypass Vulnerability (0.70 - 4.7.4)