Path traversal in Tiles - CVE-2023-49735

 

Path traversal in Tiles - CVE-2023-49735

Published: January 2, 2026


Vulnerability identifier: #VU120878
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2023-49735
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences while resolving XML definition files in DefaultLocaleResolver.LOCALE_KEY attribute. A remote attacker can send a specially crafted HTTP request and read arbitrary files on the system or perform XXE attacks.


Affected software

Tiles
Jira Software Server
Jira Software Data Center
Jira Service Management Server
Jira Service Management Data Center

How to mitigate CVE-2023-49735

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

Jira Software Server - update to 11.2.1
Jira Software Data Center - update to 11.2.1
Jira Service Management Server - update to 11.2.1
Jira Service Management Data Center - update to 11.2.1

External References

Related Security Bulletins