interesting · Edge
Unauthenticated callers can read known files from the web roots of eight Atlassian server products.
Affects
Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo and Crowd Data Center, plus Crucible and Fisheye; self-managed enterprise collaboration and development servers.
The traversal reaches specifically named files beneath the application web root without authentication across the affected self-managed products.
Detail and 3 sources
Its ceiling is narrower than arbitrary filesystem read: the caller must know the exact path, and the disclosed scope ends at the web root.