Vulnerability Description
Affected versions of Automation for Jira - Server allowed remote attackers to read and render files as mustache templates in files inside the WEB-INF/classes & <jira-installation>/jira/bin directories via a template injection vulnerability in Jira smart values using mustache partials. The affected versions are those before version 7.1.15.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Atlassian | Automation For Jira | < 7.1.15 |
Related Weaknesses (CWE)
References
- https://jira.atlassian.com/browse/JIRAAUTOSERVER-185Issue TrackingVendor Advisory
- https://jira.atlassian.com/browse/JIRAAUTOSERVER-185Issue TrackingVendor Advisory
FAQ
What is CVE-2020-14193?
CVE-2020-14193 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Affected versions of Automation for Jira - Server allowed remote attackers to read and render files as mustache templates in files inside the WEB-INF/classes & <jira-installation>/jira/bin directories...
How severe is CVE-2020-14193?
CVE-2020-14193 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-14193?
Check the references section above for vendor advisories and patch information. Affected products include: Atlassian Automation For Jira.