Jira δÊÚȨ SSRF ·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-09-24·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-8451£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º6.5
Ó°Ïì°æ±¾
Jira < 8.4.0
·ì϶¸ÅÊö
Atlassian JiraÊǰĴóÀûÑÇAtlassian¹«Ë¾µÄÒ»Ì×ȱµã¸ú×ÙÖÎÀíϵͳ¡£¸ÃÏµÍ³ÖØÒªÓÃÓÚ¶Ô¹¤×÷Öи÷ÀàÎÊÌ⡢ȱµã½øÐиú×ÙÖÎÀí¡£
Jira µÄ /plugins/servlet/gadgets/makeRequest ×ÊÔ´´æÔÚ SSRF ·ì϶£¬ÔÒòÔÚÓÚ JiraWhitelist Õâ¸öÀà´æÔÚÂ߼ȱµã¡£ÔÚÓ×ÓÚ 8.4.0 µÄ Jira °æ±¾ÖУ¬¹¥»÷ÕßÄܹ»ÒÔ Jira ·þÎñ¶ËµÄÉí·Ý½Ó¼ûÄÚÍø×ÊÔ´£¬²¢ÇҸ÷ì϶ÎÞÐèÈκÎÍ´´¦¼´¿É´¥·¢¡£
·ì϶ÑéÖ¤
ÔÝÎÞPOC/EXP¡£
½¨¸´½¨Òé
https://jira.atlassian.com/browse/JRASERVER-69793
²Î¿¼Á´½Ó


¾©¹«Íø°²±¸11010802024551ºÅ