Executive brief
Atlassian Jira Server and Data Center are vulnerable to path traversal via the /WEB-INF/web.xml endpoint. A remote, unauthenticated attacker can exploit this to read sensitive configuration files. This vulnerability has been observed being exploited in the wild.
Affected products
- Atlassian Jira Server < 8.5.14, 8.6.0 to < 8.13.6, 8.14.0 to < 8.16.1
- Atlassian Jira Data Center < 8.5.14, 8.6.0 to < 8.13.6, 8.14.0 to < 8.16.1
Timeline
- 2021-08-30: disclosed: Initial NVD analysis date
- 2024-11-12: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-11-12: exploited: Confirmed as exploited in the wild per CISA KEV entry