CVE-2021-39109: Path Traversal
The renderWidgetResource resource in Atlasian Atlasboard before version 1.1.9 allows remote attackers to read arbitrary files via a path traversal vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/atlasboardto a version that resolves this vulnerability.Fixed in 1.1.9 - Upgrade
Upgrade
Atlassian Atlasboardto a version that resolves this vulnerability.Fixed in 1.1.9
Event History
Frequently Asked Questions
What is the severity of CVE-2021-39109?
CVE-2021-39109 has a medium severity rating due to its potential for exploitation via path traversal.
How do I fix CVE-2021-39109?
To fix CVE-2021-39109, update Atlassian Atlasboard to version 1.1.9 or later.
What types of attacks are possible due to CVE-2021-39109?
CVE-2021-39109 can allow remote attackers to conduct file read attacks, exposing sensitive files on the server.
Is CVE-2021-39109 present in all versions of Atlasboard?
CVE-2021-39109 affects all versions of Atlassian Atlasboard prior to 1.1.9.
What systems are impacted by CVE-2021-39109?
Systems running Atlassian Atlasboard versions earlier than 1.1.9 are impacted by CVE-2021-39109.