The Jira importers plugin AttachTemporaryFile rest resource in Jira Server and Data Center before version 8.5.12, from version 8.6.0 before 8.13.4, and from version 8.14.0 before 8.15.1 allowed remote authenticated attackers to obtain the full path of the Jira application data directory via an information disclosure vulnerability in the error message when presented with an invalid filename.
History

Thu, 17 Oct 2024 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: atlassian

Published: 2021-04-14T23:45:18.560468Z

Updated: 2024-10-17T14:03:25.665Z

Reserved: 2021-01-25T00:00:00

Link: CVE-2021-26075

cve-icon Vulnrichment

Updated: 2024-08-03T20:19:19.544Z

cve-icon NVD

Status : Modified

Published: 2021-04-15T00:15:12.920

Modified: 2024-11-21T05:55:49.273

Link: CVE-2021-26075

cve-icon Redhat

No data.