CVE-2021-26086 - Atlassian Jira Server and Data Center Path Traversal Vulnerability
Project:Atlassian
Product:Jira Server and Data Center
Date Added:2024-11-12Due Date:2024-12-03
Vulnerability Name
Atlassian Jira Server and Data Center Path Traversal Vulnerability
Description
Atlassian Jira Server and Data Center contain a path traversal vulnerability that allows a remote attacker to read particular files in the /WEB-INF/web.xml endpoint.
Known To Be Used in Ransomware Campaigns?
Unknown
Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Additional Notes
https://jira.atlassian.com/browse/JRASERVER-72695
https://nvd.nist.gov/vuln/detail/CVE-2021-26086