The CachingResourceDownloadRewriteRule class in Jira Server and Jira Data Center allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.
id: CVE-2020-29453
info:
name: Jira Server Pre-Auth - Arbitrary File Retrieval (WEB-INF, META-INF
...