The CachingResourceDownloadRewriteRule class in Jira Server and Jira Data Center before version 8.5.11, from 8.6.0 before 8.13.3, and from 8.14.0 before 8.15.0 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://jira.atlassian.com/browse/JRASERVER-72014 |
![]() ![]() |
History
No history.

Status: PUBLISHED
Assigner: atlassian
Published: 2021-02-18T15:09:34.184843Z
Updated: 2024-09-17T00:15:39.961Z
Reserved: 2020-12-01T00:00:00
Link: CVE-2020-29453

No data.

Status : Modified
Published: 2021-02-22T21:15:19.553
Modified: 2024-11-21T05:24:01.957
Link: CVE-2020-29453

No data.