Reads internal configuration files like WEB-INF/web.xml through Jira's semicolon path parameter bypass in static resource serving.
Is your app exploitable through CVE-2021-26086?