Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products

Summary

A critical vulnerability affecting eight Atlassian Data Center products allows unauthenticated attackers to read specific files from the web application root directory. The attacker needs to know the exact file name and path, but cannot enumerate available files.

IFF Assessment

FOE

This vulnerability enables attackers to access sensitive files without authentication, posing a significant risk to organizations using the affected Atlassian products.

Severity

9.3 Critical

The CVSS score of 9.3 indicates a critical severity, reflecting the ability of an unauthenticated attacker to gain unauthorized read access to files within the web application root directory.

Defender Context

This critical vulnerability in widely used Atlassian products requires immediate attention from defenders. Organizations should prioritize patching or implementing mitigations for all affected Data Center products to prevent unauthorized file access. Attackers can leverage this flaw to potentially exfiltrate sensitive configuration or data files.

Read Full Story →