Jira before version 7.13.4, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1, allows remote attackers to access files in the Jira webroot under the META-INF directory via local file inclusion.
id: CVE-2019-8442
info:
name: Jira - Local File Inclusion
author: Kishore Krishna (siLLyDaddy)
...