PoC Index

CVE-2020-29453

MEDIUM 5.3EPSS 23.9%

The CachingResourceDownloadRewriteRule class in Jira Server and Jira Data Center before version 8.5.11, from 8.6.0 before 8.13.3, and from 8.14.0 before 8.15.0 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.

CVSS v3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
23.95% chance of exploitation in the next 30 days, 98th percentile
Nuclei
medium · CWE-22
Published
2021-02-18
Updated
2024-09-17

Nuclei templates (1)

References

Related