mcp-atlassian < 0.17.0 - Server-Side Request Forgery
MCP Atlassian < 0.17.0 contains a server-side request forgery caused by improper validation of custom HTTP headers in the HTTP middleware, letting unauthenticated attackers force outbound requests to arbitrary URLs, exploit requires access to the mcp-atlassian HTTP endpoint.
MCP AtlassianPoC 已收录
CVSS—