Atlassian released the following advisory last month:
CVE-2019-3394
Under the "Acknowledgement" section it says user "Magic Ice Cream Shop" discovered this vulnerability. There is no information on how Magic Ice Cream Shop did it (i.e. how a user with "Add Page" space permission can view files in <install-directory>/confluence/WEB-INF).
Would appreciate if Atlassian can release steps to reproduce this vulnerability so that we can make a determination as to whether an upgrade to fixed version is necessary.