Files
CVEs-PoC/2021/CVE-2021-26086.md
T
2024-06-18 02:51:15 +02:00

52 lines
2.5 KiB
Markdown

### [CVE-2021-26086](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-26086)
![](https://img.shields.io/static/v1?label=Product&message=Jira%20Data%20Center&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Jira%20Server&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3C%208.5.14%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=Path%20Traversal&color=brighgreen)
### Description
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in the /WEB-INF/web.xml endpoint. The affected versions are before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.16.1.
### POC
#### Reference
- http://packetstormsecurity.com/files/164405/Atlassian-Jira-Server-Data-Center-8.4.0-File-Read.html
#### Github
- https://github.com/0day404/vulnerability-poc
- https://github.com/20142995/Goby
- https://github.com/ARPSyndicate/cvemon
- https://github.com/ARPSyndicate/kenzer-templates
- https://github.com/ArrestX/--POC
- https://github.com/ColdFusionX/CVE-2021-26086
- https://github.com/HaleBera/A-NOVEL-CONTAINER-ATTACKS-DATASET-FOR-INTRUSION-DETECTION
- https://github.com/HaleBera/A-NOVEL-CONTAINER-ATTACKS-DATASET-FOR-INTRUSION-DETECTION-Deployments
- https://github.com/HimmelAward/Goby_POC
- https://github.com/Jeromeyoung/CVE-2021-26086
- https://github.com/KayCHENvip/vulnerability-poc
- https://github.com/Miraitowa70/POC-Notes
- https://github.com/Mr-xn/Penetration_Testing_POC
- https://github.com/StarCrossPortal/scalpel
- https://github.com/Threekiii/Awesome-POC
- https://github.com/UGF0aWVudF9aZXJv/Atlassian-Jira-pentesting
- https://github.com/Z0fhack/Goby_POC
- https://github.com/anonymous364872/Rapier_Tool
- https://github.com/apif-review/APIF_tool_2024
- https://github.com/d4n-sec/d4n-sec.github.io
- https://github.com/k0mi-tg/CVE-POC
- https://github.com/lions2012/Penetration_Testing_POC
- https://github.com/manas3c/CVE-POC
- https://github.com/nomi-sec/PoC-in-GitHub
- https://github.com/pen4uin/awesome-vulnerability-research
- https://github.com/pen4uin/vulnerability-research
- https://github.com/pen4uin/vulnerability-research-list
- https://github.com/sushantdhopat/JIRA_testing
- https://github.com/whoforget/CVE-POC
- https://github.com/winterwolf32/CVE-S---Penetration_Testing_POC-
- https://github.com/xinyisleep/pocscan
- https://github.com/xuetusummer/Penetration_Testing_POC
- https://github.com/youcans896768/APIV_Tool
- https://github.com/youwizard/CVE-POC