Jira δÊÚȨ SSRF Îó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-09-24Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-8451£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º6.5
Ó°Ïì°æ±¾
Jira < 8.4.0
Îó²î¸ÅÊö
Atlassian JiraÊǰĴóÀûÑÇAtlassian¹«Ë¾µÄÒ»Ì×ȱÏݸú×ÙÖÎÀíϵͳ¡£¸ÃϵͳÖ÷ÒªÓÃÓÚ¶ÔÊÂÇéÖÐÖÖÖÖÎÊÌ⡢ȱÏݾÙÐиú×ÙÖÎÀí¡£
Jira µÄ /plugins/servlet/gadgets/makeRequest ×ÊÔ´±£´æ SSRF Îó²î£¬Ôµ¹ÊÔÓÉÔÚÓÚ JiraWhitelist Õâ¸öÀà±£´æÂ߼ȱÏÝ¡£ÔÚСÓÚ 8.4.0 µÄ Jira °æ±¾ÖУ¬¹¥»÷Õß¿ÉÒÔÒÔ Jira ·þÎñ¶ËµÄÉí·Ý»á¼ûÄÚÍø×ÊÔ´£¬²¢ÇÒ¸ÃÎó²îÎÞÐèÈÎºÎÆ¾Ö¤¼´¿É´¥·¢¡£
Îó²îÑéÖ¤
ÔÝÎÞPOC/EXP¡£
ÐÞ¸´½¨Òé
https://jira.atlassian.com/browse/JRASERVER-69793
²Î¿¼Á´½Ó


¾©¹«Íø°²±¸11010802024551ºÅ