← back
CVE-2021-26086

CVE-2021-26086

CVSS 5.3 MEDIUMEPSS 100.0%● KEVCWE-22
In short

A path traversal vulnerability in Jira Server and Data Center allows attackers to read sensitive files by manipulating file paths in a specific endpoint. This could expose configuration files and other confidential information stored on the server.

Technical detail

The vulnerability exists in the /WEB-INF/web.xml endpoint and allows unauthenticated remote attackers to traverse directory structures and access arbitrary files via path manipulation (CWE-22). Affected versions include Jira Server/Data Center before 8.5.14, 8.6.0–8.13.5, and 8.14.0–8.16.0; successful exploitation may disclose sensitive configuration and application data.

Summary generated and translated by AI from the official description.
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in the /WEB-INF/web.xml endpoint. The affected versions are before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.16.1.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →