The CachingResourceDownloadRewriteRule class in Jira Server and Jira Data Center allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.
View the template here CVE-2020-29453.yaml
References:
https://github.com/ARPSyndicate/cvemon