CVE-2021-26086

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
16/08/2021
Last modified:
24/10/2025

Description

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in the /WEB-INF/web.xml endpoint. The affected versions are before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.16.1.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:atlassian:jira_data_center:*:*:*:*:*:*:*:* 8.5.14 (excluding)
cpe:2.3:a:atlassian:jira_data_center:*:*:*:*:*:*:*:* 8.6.0 (including) 8.13.6 (excluding)
cpe:2.3:a:atlassian:jira_data_center:*:*:*:*:*:*:*:* 8.14.0 (including) 8.16.1 (excluding)
cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:* 8.5.14 (excluding)
cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:* 8.6.0 (including) 8.13.6 (excluding)
cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:* 8.14.0 (including) 8.16.1 (excluding)