CVE-2020-14193: Medium severity atlassian automation for jira vulnerability
Affected versions of Automation for Jira - Server allowed remote attackers to read and render files as mustache templates in files inside the WEB-INF/classes & <jira-installation>/jira/bin directories via a template injection vulnerability in Jira smart values using mustache partials. The affected versions are those before version 7.1.15.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-14193?
CVE-2020-14193 is classified as a critical vulnerability due to its potential for remote exploitation.
How do I fix CVE-2020-14193?
To fix CVE-2020-14193, upgrade Automation for Jira to a version greater than 7.1.15.
Which versions of Automation for Jira are affected by CVE-2020-14193?
Versions of Automation for Jira prior to 7.1.15 are affected by CVE-2020-14193.
What type of vulnerability is CVE-2020-14193?
CVE-2020-14193 is a template injection vulnerability that allows remote attackers to read and render files.
Can CVE-2020-14193 lead to unauthorized file access?
Yes, CVE-2020-14193 can lead to unauthorized file access and data exposure for affected users.