Description
The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to access files in the Jira webroot under the META-INF directory via a lax path access check.
Remediation
References
Related Vulnerabilities
WordPress Plugin Properties and Agents-Real Estate Manager Cross-Site Scripting (6.7.1)
Apache Tomcat Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-5062)
WordPress Plugin Quotes and Tips by BestWebSoft Cross-Site Scripting (1.32)
TYPO3 7PK - Security Features Vulnerability (CVE-2016-5091)
WordPress Plugin Widget for Facebook Page Feeds Cross-Site Scripting (5.0)