CVE-2020-29453: Path Traversal
The CachingResourceDownloadRewriteRule class in Jira Server and Jira Data Center before version 8.5.11, from 8.6.0 before 8.13.3, and from 8.14.0 before 8.15.0 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-29453?
CVE-2020-29453 is a vulnerability in Jira Server and Jira Data Center that allows unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories.
What is the severity of CVE-2020-29453?
The severity of CVE-2020-29453 is medium with a CVSS score of 5.3.
How can an attacker exploit CVE-2020-29453?
An attacker can exploit CVE-2020-29453 by sending a specially crafted request to the vulnerable server and reading arbitrary files.
Which versions of Jira Server and Jira Data Center are affected by CVE-2020-29453?
Jira Server versions 8.5.10 to 8.5.11, 8.6.0 to 8.13.3, and 8.14.0 to 8.15.0, as well as Jira Data Center versions 8.6.0 to 8.13.3 and 8.14.0 to 8.15.0 are affected by CVE-2020-29453.
How can I mitigate CVE-2020-29453?
To mitigate CVE-2020-29453, update Jira Server or Jira Data Center to version 8.5.11, 8.15.0, or a later patch release.