Jira before version 7.13.4, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1, allows remote attackers to access files in the Jira webroot under the META-INF directory via local file inclusion.
View the template here CVE-2019-8442.yaml
References:
https://github.com/ARPSyndicate/cvemon