CVE-2019-8442
Jira CachingResourceDownloadRewriteRule class Security Bypass
Record summary
CVE-2019-8442 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to access files in the Jira webroot under the META-INF directory via a lax path access check.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Nov 17, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | Before 7.13.4 | affected | |
| 8.0.0 | affected | ||
| Before 8.0.4 | affected | ||
| 8.1.0 | affected | ||
| Before 8.1.1 | affected | ||
Jira Server and Data CenterBrowse Atlassian / Jira Server and Data Center | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryHIGHJira - Local File InclusionCVSS 7.5
Jira before version 7.13.4, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1, allows remote attackers to access files in the Jira webroot under the META-INF directory via local file inclusion.
Impact
This vulnerability can result in sensitive information exposure, unauthorized access to files, and potential compromise of the Jira application.
Remediation
Apply the latest security patches or updates provided by Atlassian to mitigate the vulnerability.
Source: ProjectDiscovery