The Jira importers plugin AttachTemporaryFile rest resource in Jira Server and Data Center before version 8.5.12, from version 8.6.0 before 8.13.4, and from version 8.14.0 before 8.15.1 allowed remote authenticated attackers to obtain the full path of the Jira application data directory via an information disclosure vulnerability in the error message when presented with an invalid filename.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://jira.atlassian.com/browse/JRASERVER-72316 |
![]() ![]() |
History
Thu, 17 Oct 2024 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: atlassian
Published:
Updated: 2024-10-17T14:03:25.665Z
Reserved: 2021-01-25T00:00:00
Link: CVE-2021-26075

Updated: 2024-08-03T20:19:19.544Z

Status : Modified
Published: 2021-04-15T00:15:12.920
Modified: 2024-11-21T05:55:49.273
Link: CVE-2021-26075

No data.