CVE-2021-26086
בינונית 5.3 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Atlassian Jira Server and Data Center Path Traversal Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in the /WEB-INF/web.xml endpoint. The affected versions are before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.16.1.
מדדים
- CVSS 3.1
-
5.3 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N - EPSS — סבירות ניצול
- 100% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-22
מוצרים מושפעים
atlassian: jira data center; atlassian: jira server
קישורים
- https://jira.atlassian.com/browse/JRASERVER-72695 Issue TrackingVendor Advisory
- https://jira.atlassian.com/browse/JRASERVER-72695 Issue TrackingVendor Advisory
- http://packetstormsecurity.com/files/164405/Atlassian-Jira-Server-Data-Center-… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/164405/Atlassian-Jira-Server-Data-Center-… ExploitThird Party AdvisoryVDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource