{"api_version":"1","generated_at":"2026-07-23T11:21:19+00:00","cve":"CVE-2019-8442","urls":{"html":"https://cve.report/CVE-2019-8442","api":"https://cve.report/api/cve/CVE-2019-8442.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-8442","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-8442"},"summary":{"title":"CVE-2019-8442","description":"The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to access files in the Jira webroot under the META-INF directory via a lax path access check.","state":"PUBLIC","assigner":"security@atlassian.com","published_at":"2019-05-22 18:29:00","updated_at":"2022-04-22 20:10:00"},"problem_types":["NVD-CWE-noinfo"],"metrics":[],"references":[{"url":"https://jira.atlassian.com/browse/JRASERVER-69241","name":"https://jira.atlassian.com/browse/JRASERVER-69241","refsource":"MISC","tags":["Issue Tracking","Vendor Advisory"],"title":"[JRASERVER-69241] Lax path access check allowing access to webroot files in the META-INF directory in the CachingResourceDownloadRewriteRule class - CVE-2019-8442 - Create and track feature requests for Atlassian products.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/108460","name":"108460","refsource":"BID","tags":[],"title":"Malformed Request","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-8442","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-8442","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"8442","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"atlassian","cpe5":"jira","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"8442","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"atlassian","cpe5":"jira","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"8442","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"atlassian","cpe5":"jira_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security@atlassian.com","DATE_PUBLIC":"2019-05-08T00:00:00","ID":"CVE-2019-8442","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Atlassian","product":{"product_data":[{"product_name":"Jira","version":{"version_data":[{"version_value":"7.13.4","version_affected":"<"},{"version_value":"8.0.0","version_affected":">="},{"version_value":"8.0.4","version_affected":"<"},{"version_value":"8.1.0","version_affected":">="},{"version_value":"8.1.1","version_affected":"<"}]}}]}}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to access files in the Jira webroot under the META-INF directory via a lax path access check."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Information Exposure"}]}]},"references":{"reference_data":[{"url":"https://jira.atlassian.com/browse/JRASERVER-69241","refsource":"MISC","name":"https://jira.atlassian.com/browse/JRASERVER-69241"},{"refsource":"BID","name":"108460","url":"http://www.securityfocus.com/bid/108460"}]}},"nvd":{"publishedDate":"2019-05-22 18:29:00","lastModifiedDate":"2022-04-22 20:10:00","problem_types":["NVD-CWE-noinfo"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:atlassian:jira:*:*:*:*:*:*:*:*","versionEndExcluding":"7.13.4","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:*","versionStartIncluding":"8.1.0","versionEndExcluding":"8.1.1","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:*","versionStartIncluding":"8.0.0","versionEndExcluding":"8.0.4","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"8442","Ordinal":"146278","Title":"CVE-2019-8442","CVE":"CVE-2019-8442","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"8442","Ordinal":"1","NoteData":"The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to access files in the Jira webroot under the META-INF directory via a lax path access check.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"8442","Ordinal":"2","NoteData":"2019-05-22","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"8442","Ordinal":"3","NoteData":"2019-05-27","Type":"Other","Title":"Modified"}]}}}