The CachingResourceDownloadRewriteRule class in Jira Server and Jira Data Center before version 8.5.11, from 8.6.0 before 8.13.3, and from 8.14.0 before 8.15.0 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://jira.atlassian.com/browse/JRASERVER-72014 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: atlassian
Published: 2021-02-18T15:09:34.184843Z
Updated: 2024-09-17T00:15:39.961Z
Reserved: 2020-12-01T00:00:00
Link: CVE-2020-29453
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-02-22T21:15:19.553
Modified: 2024-11-21T05:24:01.957
Link: CVE-2020-29453
Redhat
No data.