CVE-2020-14193
CVE-2020-14193
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 0.8%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
30 Nov 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Affected versions of Automation for Jira - Server allowed remote attackers to read and render files as mustache templates in files inside the WEB-INF/classes & <jira-installation>/jira/bin directories via a template injection vulnerability in Jira smart values using mustache partials. The affected versions are those before version 7.1.15.
Affected products
Atlassian · Automation for JiraWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →