Impact
An unauthenticated remote attacker can read specific files located in the web application root directory of affected Atlassian products. The vulnerability requires prior knowledge of the exact file name and path, but it does not provide directory enumeration. This flaw can lead to disclosure of highly sensitive information such as configuration files, logs, or other internal documents, thereby compromising confidentiality and potentially enabling further attacks.
Affected Systems
The flaw affects a wide range of Atlassian Data Center and Server editions. Bitbucket Data Center versions starting at 4.6.0 are vulnerable until patch 9.4.26, 10.2.8 or 10.5.1. Confluence Data Center from 5.10.0 is affected until 9.2.26 or 10.2.19. Crowd Data Center from 2.11.0 requires upgrade to 6.3.7, 7.0.3, 7.1.1 or 7.2.4. Jira Software Data Center from 7.1.0 must be patched to 9.12.40, 10.3.26 or 11.3.12, as does Jira Service Management Data Center from 3.1.0. Bamboo Data Center from 7.0.1 needs at least 10.2.24 or 12.1.12. Crucible and Fisheye are fixed at 4.9.15.
Risk and Exploitability
The CVSS score of 9.3 classifies this as critical, and although the EPSS score is not available, the lack of a KEV listing does not diminish its inherent severity. The vulnerability is exploitable over the network without authentication, requiring only a crafted request that points to a known file path. As there is no directory listing capability, the attacker must have prior knowledge or guess the file location, limiting the attack surface relative to fully enumerative flaws. Nonetheless, the potential for confidential data leakage warrants immediate attention.
OpenCVE Enrichment