Executive brief
Atlassian Atlasboard, a tool used to build and display wallboards, contains a security flaw that allows unauthorized users to access files on the server. By sending a specially crafted request, an attacker could read sensitive system files or configuration data. This could lead to the exposure of private information or credentials stored on the host machine.
Technical details
A path traversal vulnerability exists in the `renderWidgetResource` function within Atlassian Atlasboard before version 1.1.9. The vulnerability arises because the application fails to properly sanitize the `resource` parameter before using it to construct a file path. A remote, unauthenticated attacker can exploit this by using directory traversal sequences (e.g., `../../`) to escape the intended widget directory and read arbitrary files from the underlying server's file system. The issue is fixed in version 1.1.9.
Affected products
- Atlassian atlasboard < 1.1.9
Timeline
- 2021-09-01: advisory: NVD published the CVE record.
- 2021-09-02: disclosed: GitHub Advisory published.
- 2021-09-02: patched: Fix released in version 1.1.9.
References
- https://arxiv.org/abs/2506.04962
- https://arxiv.org/pdf/2506.04962
- https://bitbucket.org/atlassian/atlasboard/commits/9c03df09f09399e2601010466e8ba3a28236eb9c
- https://bitbucket.org/atlassian/atlasboard/pull-requests/91/buildeng-19379-apply-only-the-path
- https://bitbucket.org/atlassian/atlasboard/src/master