CVE-2020-29453
Jira Server Pre-Auth - Arbitrary File Retrieval (WEB-INF, META-INF)
Record summary
CVE-2020-29453 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.
Description
The CachingResourceDownloadRewriteRule class in Jira Server and Jira Data Center before version 8.5.11, from 8.6.0 before 8.13.3, and from 8.14.0 before 8.15.0 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Jira Data CenterBrowse Atlassian / Jira Data Center | CVE List | Before 8.5.11 | affected |
| 8.6.0 | affected | ||
| Before 8.13.3 | affected | ||
| 8.14.0 | affected | ||
| Before 8.15.0 | affected | ||
Jira ServerBrowse Atlassian / Jira Server | CVE List | Before 8.5.11 | affected |
| 8.6.0 | affected | ||
| Before 8.13.3 | affected | ||
| 8.14.0 | affected | ||
| Before 8.15.0 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMJira Server Pre-Auth - Arbitrary File Retrieval (WEB-INF, META-INF)CVSS 5.3
The CachingResourceDownloadRewriteRule class in Jira Server and Jira Data Center allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.
Impact
An attacker can retrieve sensitive files containing configuration information, potentially leading to further exploitation or unauthorized access.
Remediation
Apply the necessary patches or updates provided by Atlassian to fix the vulnerability.
Source: ProjectDiscovery