S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2019-8442 Scanner

CVE-2019-8442 scanner - Directory Traversal vulnerability in Atlassian Jira

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.8k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-8442
7.5
CVSS

The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to access files in the Jira webroot under the META-INF directory via a lax path access check.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Jiraby Atlassian
AFFECTED< 7.13.4SAFE ✓≥ 7.13.4
Updated Aug 21, 2026View on NVD →
Detail

Atlassian Jira is an application developed by Atlassian that enables teams to manage their projects, collaborate, and track their progress through tasks and processes. Jira is one of the most popular project management tools in the industry, used by all types of teams, from software developers to marketing departments. The platform offers an intuitive and user-friendly interface that helps teams to increase their productivity and streamline their workflows.

One of the vulnerabilities detected in Jira is the CVE-2019-8442, which impacted several versions of the application, including version 7.13.4, versions 8.0.0 to 8.0.4, and versions 8.1.0 to 8.1.1. This vulnerability allowed remote attackers to gain access to files in the Jira webroot under the META-INF directory through a lax path access check. This could enable the attacker to execute arbitrary code on the system, compromise sensitive data, and launch further attacks on the infrastructure.

If exploited, the CVE-2019-8442 vulnerability in Jira can lead to severe consequences, such as loss or theft of critical data, service disruption, reputational damage, and financial loss for the company. With access to sensitive information, attackers can carry out phishing attacks or sell confidential data on the black market, causing irreparable harm to the organization.

By using s4e.io's pro features, those who read this article can quickly and easily learn about vulnerabilities in their digital assets. The platform provides comprehensive scanning and analysis of web applications, networks, and databases to identify any security flaws and potential attack vectors. The pro features also offer detailed reporting and analytics to help organizations stay on top of their security posture and mitigate risks effectively.

 

REFERENCES

Solution Advice

To protect against this vulnerability, it's recommended to take the following precautions:

  • Apply the latest security patches and updates to Jira as soon as they become available.
  • Use strong and unique passwords for all Jira accounts and enable two-factor authentication.
  • Implement a web application firewall (WAF) to block malicious traffic and prevent attacks.
  • Restrict access to the Jira webroot directory and apply secure file permissions.
  • Regularly conduct vulnerability scans and penetration tests to identify and address any security issues.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-8442 scanner - Directory Traversal vulnerability in Atlassian Jira | S4E