Information disclosure - full path disclosure

XMLWordPrintable

    • 6.02

      Jira displays charts on the dashboard by writting a temporary file in Jira "tmp" folder and reading it through a page called "charts"
      When the filename provided to this page is not present, an error message displays the full path to the "tmp" folder, which lies in Jira directory.
      This is a vulnerability.

              Assignee:
              Unassigned
              Reporter:
              Vincent Leleu
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                Resolved: