CVE Database
/

CVE-2020-14193

Back to search

CVE-2020-14193

Published: Nov 30, 2020

Modified: Sep 17, 2024

PUBLISHED

Description

Affected versions of Automation for Jira - Server allowed remote attackers to read and render files as mustache templates in files inside the WEB-INF/classes & <jira-installation>/jira/bin directories via a template injection vulnerability in Jira smart values using mustache partials. The affected versions are those before version 7.1.15.

VendorProductVersions

Atlassian

Automation for Jira

affected
unspecified - < 7.1.15

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now