Atlassian JIRA Server和Atlassian JIRA Data Center都是澳大利亚Atlassian公司的产品。Atlassian JIRA Server是一套缺陷跟踪管理系统的服务器版本。该系统主要用于对工作中各类问题、缺陷进行跟踪管理。Atlassian JIRA Data Center是Atlassian JIRA的数据中心版本。 Jira Server and Jira Data Center 存在安全漏洞,攻击者可利用该漏洞通过错误的路径访问检查读取WEB-INF和ME
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Atlassian | Jira Server | unspecified ~ 8.5.11 | - |
|
| Atlassian | Jira Data Center | unspecified ~ 8.5.11 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | The CachingResourceDownloadRewriteRule class in Jira Server and Jira Data Center allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2020/CVE-2020-29453.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2021-26068 | Atlassian JIRA Server 注入漏洞 | |
| CVE-2020-36233 | Atlassian Bitbucket Server and Data Center 安全漏洞 | |
| CVE-2020-29448 | Atlassian Confluence Server 和 Confluence Data Center 安全漏洞 |
No comments yet