#VU21326 Improper access control in Jira Software - CVE-2019-8442
Published: September 25, 2019
Jira Software
Atlassian
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in the "CachingResourceDownloadRewriteRule" class. A remote attacker can bypass implemented security restrictions and gain unauthorized access to files in the Jira webroot under the META-INF directory via a lax path access check.