Record summary

CVE-2020-29453 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

The CachingResourceDownloadRewriteRule class in Jira Server and Jira Data Center before version 8.5.11, from 8.6.0 before 8.13.3, and from 8.14.0 before 8.15.0 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE ListBefore 8.5.11affected
8.6.0affected
Before 8.13.3affected
8.14.0affected
Before 8.15.0affected
CVE ListBefore 8.5.11affected
8.6.0affected
Before 8.13.3affected
8.14.0affected
Before 8.15.0affected

Nuclei templates

1
ProjectDiscoveryMEDIUMJira Server Pre-Auth - Arbitrary File Retrieval (WEB-INF, META-INF)CVSS 5.3

The CachingResourceDownloadRewriteRule class in Jira Server and Jira Data Center allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.

Impact

An attacker can retrieve sensitive files containing configuration information, potentially leading to further exploitation or unauthorized access.

Remediation

Apply the necessary patches or updates provided by Atlassian to fix the vulnerability.

WeaknessesCWE-22
Authorsdwisiswant0
Template tagscvecve2020atlassianjiralfiintrusivevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:atlassian:data_center:*:*:*:*:*:*:*:*
Shodan: http.component:"Atlassian Jira"
Shodan: http.component:"atlassian jira"

Source: ProjectDiscovery

References

2