QID 150371
Date Published: 2021-10-11
QID 150371: Atlassian Jira Server and Data Center Arbitrary File Read (CVE-2021-26086)
Jira is a proprietary issue tracking product, developed by Atlassian. It provides bug tracking, issue tracking, and project management functions.
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in the /WEB-INF/web.xml endpoint.
Affected version:
Atlassian Jira Server and Data Center version prior to 8.5.14
Atlassian Jira Server and Data Center version from 8.6.0 to 8.13.5
Atlassian Jira Server and Data Center version from 8.14.0 to 8.16.0
QID Detection Logic (Unauthenticated) :
This QID sends a HTTP GET request to access restricted resources "web.xml" and/or "pom.properties" and based on the response confirms if the target is vulnerable.
Successful exploitation of the vulnerability may allow remote attackers to read sensitive files on the target server.
- JRASERVER-72695 -
jira.atlassian.com/browse/JRASERVER-72695
CVEs related to QID 150371
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JRASERVER-72695 |
|