CVE-2019-8442
HIGH 7.5EPSS 59.8%
The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to access files in the Jira webroot under the META-INF directory via a lax path access check.
- CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - CVSS v2.0
- 5.0 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N - EPSS
- 59.83% chance of exploitation in the next 30 days, 99th percentile
- Nuclei
- high
- Published
- 2019-05-22
- Updated
- 2024-09-16
Nuclei templates (1)
Exploit collections (2)
- chaitin/xray/blob/master/pocs/jira-cve-2019-8442.yml
- zan8in/afrog/blob/main/pocs/afrog-pocs/CVE/2019/CVE-2019-8442.yaml