Atlassian JIRA Importers Plugin Arbitrary File Creation Vulnerability
BID:65841
Info
Atlassian JIRA Importers Plugin Arbitrary File Creation Vulnerability
| Bugtraq ID: | 65841 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-2313 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 26 2014 12:00AM |
| Updated: | Mar 11 2014 02:13AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Atlassian JIRA Importers Plugin Arbitrary File Creation Vulnerability
Atlassian JIRA Importers plugin is prone to arbitrary-file-creation vulnerability.
An attacker can exploit this issue to create arbitrary files on the server by using a specially crafted request with directory-traversal sequences ('../') .
Atlassian JIRA prior to 6.0.5 are vulnerable.
Atlassian JIRA Importers plugin is prone to arbitrary-file-creation vulnerability.
An attacker can exploit this issue to create arbitrary files on the server by using a specially crafted request with directory-traversal sequences ('../') .
Atlassian JIRA prior to 6.0.5 are vulnerable.
Exploit / POC
Atlassian JIRA Importers Plugin Arbitrary File Creation Vulnerability
An attacker can use readily available tools to exploit this issue.
An attacker can use readily available tools to exploit this issue.
Solution / Fix
Atlassian JIRA Importers Plugin Arbitrary File Creation Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Atlassian JIRA Importers Plugin Arbitrary File Creation Vulnerability
References:
References:
- Atlassian JIRA Homepage (Atlassian)