Lucene search

K
atlassianSecurity-metrics-botATLASSIAN:JRASERVER-69241
HistoryApr 29, 2019 - 3:50 a.m.

Lax path access check allowing access to webroot files in the META-INF directory in the CachingResourceDownloadRewriteRule class - CVE-2019-8442

2019-04-2903:50:39
security-metrics-bot
jira.atlassian.com
160

EPSS

0.971

Percentile

99.8%

The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to access files in the Jira webroot under the META-INF directory via a lax path access check.

EPSS

0.971

Percentile

99.8%