QID 730154
Date Published: 2021-08-17
QID 730154: Atlassian Jira Server And Data Center Path traversal Vulnerability(JRASERVER-72695)
Jira is a proprietary issue tracking product, developed by Atlassian. It provides bug tracking, issue tracking, and project management functions.
CVE-2021-26086: Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in the /WEB-INF/web.xml endpoint.
Affected version:
Atlassian Jira Server and Data Center version prior to 8.5.14
Atlassian Jira Server and Data Center version from 8.6.0 and prior to 8.13.6
Atlassian Jira Server and Data Center version from 8.14.0 and prior to 8.16.1
QID Detection Logic:(Unauthenticated)
It checks for vulnerable version of Atlassian Jira.
Successful exploitation of this vulnerability may allow a remote attacker to read particular files from the target system.
- JRASERVER-72695 -
jira.atlassian.com/browse/JRASERVER-72695
CVEs related to QID 730154
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JRASERVER-72695 |
|