Описание
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in the /WEB-INF/web.xml endpoint. The affected versions are before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.16.1.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- Issue TrackingVendor Advisory
- ExploitThird Party AdvisoryVDB Entry
- Issue TrackingVendor Advisory
- US Government Resource
Уязвимые конфигурации
Конфигурация 1Версия до 8.5.14 (исключая)Версия от 8.6.0 (включая) до 8.13.6 (исключая)Версия от 8.14.0 (включая) до 8.16.1 (исключая)Версия до 8.5.14 (исключая)Версия от 8.6.0 (включая) до 8.13.6 (исключая)Версия от 8.14.0 (включая) до 8.16.1 (исключая)
Одно из
cpe:2.3:a:atlassian:jira_data_center:*:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:jira_data_center:*:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:jira_data_center:*:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:*
EPSS
Процентиль: 100%
0.94189
Критический
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-22
CWE-22
Связанные уязвимости
CVSS3: 5.3
github
больше 3 лет назад
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in the /WEB-INF/web.xml endpoint. The affected versions are before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.16.1.
EPSS
Процентиль: 100%
0.94189
Критический
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-22
CWE-22