PT-2020-13922 · Atlassian · Automation For Jira

David Black

·

Published

2020-11-30

·

Updated

2022-02-01

·

CVE-2020-14193

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Automation for Jira - Server versions prior to 7.1.15
Description The issue allows remote attackers to read and render files as mustache templates in files inside the WEB-INF/classes and jira-installation/jira/bin directories via a template injection vulnerability in Jira smart values using mustache partials.
Recommendations For versions prior to 7.1.15, update to version 7.1.15 or later to resolve the issue. As a temporary workaround, consider restricting access to the mustache template functionality in Jira smart values to minimize the risk of exploitation.

Fix

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-14193

Affected Products

Automation For Jira