Record summary

CVE-2019-8442 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to access files in the Jira webroot under the META-INF directory via a lax path access check.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 17, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE ListBefore 7.13.4affected
8.0.0affected
Before 8.0.4affected
8.1.0affected
Before 8.1.1affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryHIGHJira - Local File InclusionCVSS 7.5

Jira before version 7.13.4, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1, allows remote attackers to access files in the Jira webroot under the META-INF directory via local file inclusion.

Impact

This vulnerability can result in sensitive information exposure, unauthorized access to files, and potential compromise of the Jira application.

Remediation

Apply the latest security patches or updates provided by Atlassian to mitigate the vulnerability.

AuthorsKishore Krishna (siLLyDaddy)
Template tagscvecve2019atlassianjiralfiintrusivevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:atlassian:jira:*:*:*:*:*:*:*:*
Shodan: http.component:"Atlassian Jira"
Shodan: http.component:"atlassian jira"
Shodan: http.component:"atlassian confluence"
Shodan: cpe:"cpe:2.3:a:atlassian:jira"

Source: ProjectDiscovery

References

3