CVE-2014-2314: Path Traversal
Published Mar 7, 2014
·Updated
Directory traversal vulnerability in the Issue Collector plugin in Atlassian JIRA before 6.0.4 allows remote attackers to create arbitrary files via unspecified vectors.
Affected Software
10 affected components
Atlassian Jira<=6.0.3
Atlassian Jira=6.0
Atlassian Jira=6.0.1
Atlassian Jira=6.0.2
Microsoft Windows
All of the following
Any of the following
Atlassian Jira<=6.0.3
Atlassian Jira=6.0
Atlassian Jira=6.0.1
Atlassian Jira=6.0.2
Microsoft Windows
Event History
Mar 7, 2014
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Mar 9, 2014
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-2314?
CVE-2014-2314 is classified as a medium severity vulnerability due to its potential for directory traversal and arbitrary file creation.
2
How do I fix CVE-2014-2314?
To remediate CVE-2014-2314, upgrade Atlassian JIRA to version 6.0.4 or later.
3
Which versions of JIRA are affected by CVE-2014-2314?
CVE-2014-2314 affects Atlassian JIRA versions prior to 6.0.4, including 6.0, 6.0.1, 6.0.2, and 6.0.3.
4
What kind of attacks can exploit CVE-2014-2314?
Attackers can exploit CVE-2014-2314 to perform directory traversal attacks, leading to the creation of arbitrary files on the server.
5
Is CVE-2014-2314 a critical vulnerability?
While CVE-2014-2314 is not critical, it poses significant risks if exploited, warranting a prompt fix.